mm/vma: correctly unaccount on mmap_prepare() failure
Summary
| CVE | CVE-2026-98224 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 09:18:09 UTC |
| Updated | 2026-10-06 09:18:09 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: mm/vma: correctly unaccount on mmap_prepare() failure __mmap_setup() accounts memory for relevant mappings via: security_vm_enough_memory_mm() -> __vm_enough_memory() -> vm_acct_memory() If __mmap_setup() fails, this indicates that this accounting did not take place, and thus it's appropriate for __mmap_region() to jump to abort_munmap. However if call_mmap_prepare() fails, it also jumps there and any accounted memory is not correctly unaccounted. Fix this by handling each error separately. |
Risk And Classification
EPSS: 0.001730000 probability, percentile 0.061500000 (date 2026-10-06)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected c84bf6dd2b836b49bb2662668ff1692350d28236 fb5400bff669c8bad3d4ec09287d9b461e89e5f1 git | Not specified |
| CNA | Linux | Linux | affected c84bf6dd2b836b49bb2662668ff1692350d28236 8fdc521d438fbf0d22c13d51d55d5dd82d7202b2 git | Not specified |
| CNA | Linux | Linux | affected c84bf6dd2b836b49bb2662668ff1692350d28236 6cc27d82196385fe06853319f74312a7d8019726 git | Not specified |
| CNA | Linux | Linux | affected 6.16 | Not specified |
| CNA | Linux | Linux | unaffected 6.16 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.54 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.8 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc4 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/fb5400bff669c8bad3d4ec09287d9b461e89e5f1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6cc27d82196385fe06853319f74312a7d8019726 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8fdc521d438fbf0d22c13d51d55d5dd82d7202b2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.