---
id: CVE-2026-98223
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mm: filemap: retain mapped dropbehind folios

  Fault-around can map ready dropbehind folios without going through the
  normal page-cache lookup that clears dropbehind
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mm: filemap: retain mapped dropbehind folios

  Fault-around can map ready dropbehind folios without going through the
  normal page-cache lookup that clears dropbehind.  A…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= fb7d3bc4149395c1ae99029c852eab6c28fc3c88 <
    2897601dffe576fcd87a4259102f41f7fb0cbfc8
  - >-
    Linux >= fb7d3bc4149395c1ae99029c852eab6c28fc3c88 <
    77c0fade37c80e8aa16ac048a9828249055e3f66
  - >-
    Linux >= fb7d3bc4149395c1ae99029c852eab6c28fc3c88 <
    848d2ce2fce15fbdc083fbf9691bfa72911033c4
  - Linux 6.14
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:09.290'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98223'
references:
  - url: 'https://git.kernel.org/stable/c/2897601dffe576fcd87a4259102f41f7fb0cbfc8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/77c0fade37c80e8aa16ac048a9828249055e3f66'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/848d2ce2fce15fbdc083fbf9691bfa72911033c4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.439Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

mm: filemap: retain mapped dropbehind folios

Fault-around can map ready dropbehind folios without going through the
normal page-cache lookup that clears dropbehind.  A mapping represents a
competing cached user, so retain the folio instead of forcibly unmapping
it when writeback completes.

For a mapped folio, folio_unmap_invalidate() can call
unmap_mapping_folio(), which takes i_mmap_rwsem and may sleep.  Retaining
mapped folios avoids this path when folio_end_dropbehind() runs in
non-preemptible task context.

Tal was able to trigger a sleeping-in-atomic warning due to this [1].

Unmapped dropbehind folios continue through the existing invalidation path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
