---
id: CVE-2026-93066
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  x86/mm/pat: Take cpa_lock around large-page collapse

  Loading and unloading modules concurrently on several CPUs on a KASAN
  build, with a short delay injected at the CP…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  x86/mm/pat: Take cpa_lock around large-page collapse

  Loading and unloading modules concurrently on several CPUs on a KASAN
  build, with a short delay injected at the CP…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 41d88484c71cd4f659348da41b7b5b3dbd3be1f6 <
    591b6fac9df3f43522e8ff6eed8662f8b6f1a124
  - >-
    Linux >= 41d88484c71cd4f659348da41b7b5b3dbd3be1f6 <
    fb97d1d6c20692e15247fa5c8b894b2325e38aee
  - >-
    Linux >= 41d88484c71cd4f659348da41b7b5b3dbd3be1f6 <
    1aac65f3e651334259ecb2a5f5ddb81c01f02599
  - Linux 6.15
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:00.380'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93066'
references:
  - url: 'https://git.kernel.org/stable/c/1aac65f3e651334259ecb2a5f5ddb81c01f02599'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/591b6fac9df3f43522e8ff6eed8662f8b6f1a124'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fb97d1d6c20692e15247fa5c8b894b2325e38aee'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.766Z'
epss: 0.00166
epssPercentile: 0.06276
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

x86/mm/pat: Take cpa_lock around large-page collapse

Loading and unloading modules concurrently on several CPUs on a KASAN
build, with a short delay injected at the CPA page-table lookup to
widen the window, faults within minutes:

  BUG: KASAN: use-after-free in __change_page_attr+0x7cc/0x7e0
  Write of size 8 at addr ffff888181139718 by task modprobe
  ...
  The buggy address belongs to the physical page:
   pfn:0x181139 ... page_type: f2(table)

cpa_collapse_large_pages() rebuilds a leaf PMD from its 4K PTEs and
frees the old PTE-table pages, while __change_page_attr() fetches a
PTE pointer from a lockless lookup_address_in_pgd_attr() and writes
it with set_pte_atomic() only later. When module text is served from
a shared large ROX mapping the two run on the same PMD:

  CPU A (module load)              CPU B (module finalize)
  -------------------              -----------------------
  execmem_make_temp_rw
   set_memory_nx
    __change_page_attr
     split 2M -> 4K table P
     kpte = &P[i]  (lockless)
                                   execmem_restore_rox
                                    set_memory_rox (CPA_COLLAPSE)
                                     cpa_collapse_large_pages
                                      rebuild leaf PMD
                                      flush_tlb_all
                                      pagetable_free(P)
     set_pte_atomic(kpte, ...)
       -> writes into freed P

P is a page-table page (page_type: table), reused at once, so the
write corrupts whatever got the page next: a bad-pte or bad-page
splat, or a fatal fault once P has been turned into read-only text.

The flush_tlb_all() before the free does not close this: its IPI only
serializes against page-table walkers that run with interrupts off
(e.g. GUP-fast); the walk in __change_page_attr() runs with interrupts
on, so nothing stops it from holding a stale pointer into P.

Serialize the collapse - the PMD rebuild, TLB flush and PTE-table
free - under cpa_lock, the same lock __change_page_attr() now takes
unconditionally since commit ("x86/mm/pat: stop gating cpa_lock on
debug_pagealloc_enabled()"), so a concurrent walker can no longer
hold a pointer into a table the collapse is about to free.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
