{"id":"CVE-2026-98223","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: filemap: retain mapped dropbehind folios\n\nFault-around can map ready dropbehind folios without going through the\nnormal page-cache lookup that clears dropbehind","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: filemap: retain mapped dropbehind folios\n\nFault-around can map ready dropbehind folios without going through the\nnormal page-cache lookup that clears dropbehind.  A…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= fb7d3bc4149395c1ae99029c852eab6c28fc3c88 < 2897601dffe576fcd87a4259102f41f7fb0cbfc8","Linux >= fb7d3bc4149395c1ae99029c852eab6c28fc3c88 < 77c0fade37c80e8aa16ac048a9828249055e3f66","Linux >= fb7d3bc4149395c1ae99029c852eab6c28fc3c88 < 848d2ce2fce15fbdc083fbf9691bfa72911033c4","Linux 6.14"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:09.290","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98223","references":[{"url":"https://git.kernel.org/stable/c/2897601dffe576fcd87a4259102f41f7fb0cbfc8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77c0fade37c80e8aa16ac048a9828249055e3f66","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/848d2ce2fce15fbdc083fbf9691bfa72911033c4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.439Z","slug":"CVE-2026-98223","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmm: filemap: retain mapped dropbehind folios\n\nFault-around can map ready dropbehind folios without going through the\nnormal page-cache lookup that clears dropbehind.  A mapping represents a\ncompeting cached user, so retain the folio instead of forcibly unmapping\nit when writeback completes.\n\nFor a mapped folio, folio_unmap_invalidate() can call\nunmap_mapping_folio(), which takes i_mmap_rwsem and may sleep.  Retaining\nmapped folios avoids this path when folio_end_dropbehind() runs in\nnon-preemptible task context.\n\nTal was able to trigger a sleeping-in-atomic warning due to this [1].\n\nUnmapped dropbehind folios continue through the existing invalidation path.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}