---
id: CVE-2026-93218
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd

  madvise_free_pte_range() checks pmd_trans_huge(*pmd) unlocked, then
  madvise_free_huge_pmd() takes pmd…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd

  madvise_free_pte_range() checks pmd_trans_huge(*pmd) unlocked, then
  madvise_free_huge_pmd() takes pmd…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 368076f52ebeecd33e10a9f80905d7508b6b6149 <
    5e3026bf736498115884d6c7bd0308ba29e0474c
  - >-
    Linux >= 368076f52ebeecd33e10a9f80905d7508b6b6149 <
    ce579dcf730ce5ed8043a5eeea18a3e6706a97e5
  - Linux 6.19
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T16:17:16.907'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93218'
references:
  - url: 'https://git.kernel.org/stable/c/5e3026bf736498115884d6c7bd0308ba29e0474c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ce579dcf730ce5ed8043a5eeea18a3e6706a97e5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T15:45:56.669Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd

madvise_free_pte_range() checks pmd_trans_huge(*pmd) unlocked, then
madvise_free_huge_pmd() takes pmd_trans_huge_lock().  pmd_is_huge()
returns true for a device-private PMD, so orig_pmd can be device-private
and enter the !pmd_present() branch.

Skip device-private PMDs in that non-present branch and continue to out
before calling pmd_folio().  Downgrade the check to VM_WARN_ON_ONCE() so
an unexpected PMD softleaf logs a warning rather than panicking.  Drop the
thp_migration_supported() guard: it expands to
IS_ENABLED(CONFIG_ARCH_SUPPORTS_PMD_SOFTLEAF), and both
pmd_is_migration_entry() and pmd_is_device_private_entry() already return
false when that config is not selected, so the guard suppresses only the
case where the warning would already be silent.

Potential trigger: an HMM-based GPU driver races with madvise(MADV_FREE):
migrate_vma_pages() flips the PMD to a device-private entry between the
caller's pmd_trans_huge() check and the callee's pmd_trans_huge_lock().

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
