CVE-2026-31589
CRITICAL
9.8
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved:
mm: call ->free_folio() directly in folio_unmap_invalidate()
We can only call filemap_free_folio() if we have a reference to (or hold a
lock on) the mapping. Otherwise, we've already removed the folio from the
mapping so it no longer pins the mapping and the mapping can be removed,
causing a use-after-free when accessing mapping->a_ops.
Follow the same pattern as __remove_mapping() and load the free_folio
function pointer before dropping the lock on the mapping. That lets us
make filemap_free_folio() static as this was the only caller outside
filemap.c.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Linux | Linux | — | fb7d3bc4149395c1ae99029c852eab6c28fc3c88 < efc52947247a21bbf79059539bbbd40f4ea76f00, fb7d3bc4149395c1ae99029c852eab6c28fc3c88 < b667df39d98a7a24be7c2a40ff0863dac1ad2cd7, fb7d3bc4149395c1ae99029c852eab6c28fc3c88 < c330e65ea59c4805d6ab6757c4ddfe8c63acef31, fb7d3bc4149395c1ae99029c852eab6c28fc3c88 < 615d9bb2ccad42f9e21d837431e401db2e471195 |
| Linux | Linux | — | 6.14, 0 < 6.14, 6.18.27 ≤ 6.18.*, 6.19.14 ≤ 6.19.* … |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (4)