{"id":"CVE-2026-89593","title":"hugetlb: only adjust reservation during unmapping if mapcount is 0","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nhugetlb: only adjust reservation during unmapping if mapcount is 0\n\nSince df7a6d1f6405, __unmap_hugepage_range can adjust reservations.  In\nthe case of folio mapped in …","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= df7a6d1f64056aec572162c5d35ed9ff86ece6f3 < b0b1b9ca80b795ed2223e76dd787db7067121fb9","Linux >= df7a6d1f64056aec572162c5d35ed9ff86ece6f3 < a3c65af20cceb7f997847727636b4017326f845d","Linux >= df7a6d1f64056aec572162c5d35ed9ff86ece6f3 < 0f001491e5a2ec69aa9d5dd6b799e5742245f9ea","Linux >= df7a6d1f64056aec572162c5d35ed9ff86ece6f3 < 5120b1e048d48596ffaec1a8412012a91adba73b","Linux 6.9"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T12:01:16.035Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-89593","references":[{"url":"https://git.kernel.org/stable/c/b0b1b9ca80b795ed2223e76dd787db7067121fb9"},{"url":"https://git.kernel.org/stable/c/a3c65af20cceb7f997847727636b4017326f845d"},{"url":"https://git.kernel.org/stable/c/0f001491e5a2ec69aa9d5dd6b799e5742245f9ea"},{"url":"https://git.kernel.org/stable/c/5120b1e048d48596ffaec1a8412012a91adba73b"}],"tags":["cve.org"],"epss":0.00125,"epssPercentile":0.02563,"ingestedAt":"2026-09-14T15:23:07.451Z","slug":"CVE-2026-89593","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nhugetlb: only adjust reservation during unmapping if mapcount is 0\n\nSince df7a6d1f6405, __unmap_hugepage_range can adjust reservations.  In\nthe case of folio mapped in both a parent and a child, if the parent\nunmaps the range first, the reservation adjustment will result in an\nunderflow of the reserved count.  Once the child unmaps the range, the\ncount is restored.  Change __unmap_hugepage_range() to check the mapcount\nbefore adjusting the reservation.\n\n## Affected\n\n- `Linux >= df7a6d1f64056aec572162c5d35ed9ff86ece6f3 < b0b1b9ca80b795ed2223e76dd787db7067121fb9`\n- `Linux >= df7a6d1f64056aec572162c5d35ed9ff86ece6f3 < a3c65af20cceb7f997847727636b4017326f845d`\n- `Linux >= df7a6d1f64056aec572162c5d35ed9ff86ece6f3 < 0f001491e5a2ec69aa9d5dd6b799e5742245f9ea`\n- `Linux >= df7a6d1f64056aec572162c5d35ed9ff86ece6f3 < 5120b1e048d48596ffaec1a8412012a91adba73b`\n- `Linux 6.9`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":197898,"id":"CVE-2026-89593","ts":1789384320862,"field":"cvss","old":"4.7","new":"7.1"},{"seq":197897,"id":"CVE-2026-89593","ts":1789384320862,"field":"severity","old":"medium","new":"high"},{"seq":183441,"id":"CVE-2026-89593","ts":1789356675381,"field":"cvss","old":"7.1","new":"4.7"},{"seq":183440,"id":"CVE-2026-89593","ts":1789356675381,"field":"severity","old":"high","new":"medium"},{"seq":153410,"id":"CVE-2026-89593","ts":1789285350401,"field":"cvss","old":null,"new":"7.1"},{"seq":153409,"id":"CVE-2026-89593","ts":1789285350401,"field":"severity","old":"none","new":"high"},{"seq":109608,"id":"CVE-2026-89593","ts":1789183732602,"field":"cvss","old":null,"new":"4.7"},{"seq":109607,"id":"CVE-2026-89593","ts":1789183732602,"field":"severity","old":"none","new":"medium"}]}