{"api_version":"1","generated_at":"2026-09-01T13:43:15+00:00","cve":"CVE-2026-72412","urls":{"html":"https://cve.report/CVE-2026-72412","api":"https://cve.report/api/cve/CVE-2026-72412.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-72412","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-72412"},"summary":{"title":"s390/mm: Fix handling of _PAGE_UNUSED pte bit","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Fix handling of _PAGE_UNUSED pte bit\n\nThe _PAGE_UNUSED softbit should not really be lying around. Its sole\npurpose is to signal to try_to_unmap_one() and try_to_migrate_one()\nthat the page can be discarded instead of being moved / swapped.\n\nKVM has no way to know why a page is being unmapped, so it sets the bit\non userspace ptes corresponding to unused guest pages every time they\nget unmapped. KVM has no reasonable way to clear the bit once the page\nis in use again.\n\nWhile set_ptes() checks and clears the bit, other paths that set new\nptes did not. This led to used pages being thrown out as if they were\nunused, causing guest corruption.\n\nFix the issue by clearing the _PAGE_UNUSED bit for present ptes in\nset_pte(), i.e. whenever a present pte is getting set. The check in\nset_ptes() is then redundant and can be removed.\n\nAlso fix gmap_helper_try_set_pte_unused() to only set the bit if the\npte is present; the _PAGE_UNUSED bit is only defined for present ptes\nand thus should not be set for non-present ptes.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:22:14","updated_at":"2026-08-17 06:19:08"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.3","severity":"CRITICAL","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.3","severity":"CRITICAL","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":9.3,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/fda07c8e4b54b9105f1ca73f0adea7b244d405f4","name":"https://git.kernel.org/stable/c/fda07c8e4b54b9105f1ca73f0adea7b244d405f4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d4bb00704a66024502261fa7a523c07420249fea","name":"https://git.kernel.org/stable/c/d4bb00704a66024502261fa7a523c07420249fea","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-72412","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72412","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c98175b7917fa81cd499b1527c4a57fd7d36711e fda07c8e4b54b9105f1ca73f0adea7b244d405f4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c98175b7917fa81cd499b1527c4a57fd7d36711e d4bb00704a66024502261fa7a523c07420249fea git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.0","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"72412","cve":"CVE-2026-72412","epss":"0.001800000","percentile":"0.077980000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:47"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["arch/s390/include/asm/pgtable.h","arch/s390/mm/gmap_helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"fda07c8e4b54b9105f1ca73f0adea7b244d405f4","status":"affected","version":"c98175b7917fa81cd499b1527c4a57fd7d36711e","versionType":"git"},{"lessThan":"d4bb00704a66024502261fa7a523c07420249fea","status":"affected","version":"c98175b7917fa81cd499b1527c4a57fd7d36711e","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["arch/s390/include/asm/pgtable.h","arch/s390/mm/gmap_helpers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.0"},{"lessThan":"7.0","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"7.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"7.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Fix handling of _PAGE_UNUSED pte bit\n\nThe _PAGE_UNUSED softbit should not really be lying around. Its sole\npurpose is to signal to try_to_unmap_one() and try_to_migrate_one()\nthat the page can be discarded instead of being moved / swapped.\n\nKVM has no way to know why a page is being unmapped, so it sets the bit\non userspace ptes corresponding to unused guest pages every time they\nget unmapped. KVM has no reasonable way to clear the bit once the page\nis in use again.\n\nWhile set_ptes() checks and clears the bit, other paths that set new\nptes did not. This led to used pages being thrown out as if they were\nunused, causing guest corruption.\n\nFix the issue by clearing the _PAGE_UNUSED bit for present ptes in\nset_pte(), i.e. whenever a present pte is getting set. The check in\nset_ptes() is then redundant and can be removed.\n\nAlso fix gmap_helper_try_set_pte_unused() to only set the bit if the\npte is present; the _PAGE_UNUSED bit is only defined for present ptes\nand thus should not be set for non-present ptes."}],"metrics":[{"cvssV3_1":{"baseScore":9.3,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bug is only reachable on s390 KVM hosts when a guest drives CMMA/ESSA page-state changes and gmap unmaps that reach gmap_helper_try_set_pte_unused() and host try_to_unmap_one()/try_to_migrate_one() on kvm->mm; there is no network or physical-bus entry point.\nAC:L - A guest can deterministically mark pages unused via ESSA, remap them through PTE-install paths that left stale _PAGE_UNUSED set, then induce host reclaim/migration with memory pressure; no attacker-uncontrollable race or rare layout is required on CMMA-enabled s390 KVM.\nPR:N - A malicious KVM guest tenant on an IBM Z/LinuxONE host with CMMA-enabled VMs needs no host root, capabilities, or /dev/kvm access—only guest supervisor memory management that issues ESSA and normal guest page reuse to trigger the stale-bit discard path.\nUI:N - No victim interaction is required; once a CMMA-enabled s390 KVM guest is running, the attacker directly drives ESSA unused marking, guest remap/fault activity, and memory-pressure workloads to trigger premature host-side page discard.\nS:C - The flaw corrupts host-kernel management of kvm->mm backing pages from guest-controlled CMMA state, discarding live present pages outside the guest security authority and enabling cross-boundary host memory corruption/disclosure primitives.\nC:H - Prematurely discarding present backing pages while guest mappings remain can free and reallocate folios, exposing prior page contents on refault and providing UAF-class read primitives consistent with memory-corruption confidentiality impact.\nI:H - Stale _PAGE_UNUSED causes try_to_unmap_one()/try_to_migrate_one() to drop in-use guest backing pages instead of swapping/migrating them, enabling arbitrary guest memory corruption and host mm metadata corruption exploitable for control-flow hijacking.\nA:H - Incorrect discard during host reclaim, migration, or unmap can panic/oops the kernel or repeatedly corrupt guest RAM, causing guest or host denial of service that the attacker can retrigger with memory-pressure workloads."}]}],"providerMetadata":{"dateUpdated":"2026-08-17T05:43:53.927Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/fda07c8e4b54b9105f1ca73f0adea7b244d405f4"},{"url":"https://git.kernel.org/stable/c/d4bb00704a66024502261fa7a523c07420249fea"}],"title":"s390/mm: Fix handling of _PAGE_UNUSED pte bit","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-72412","datePublished":"2026-08-15T05:56:34.165Z","dateReserved":"2026-08-09T03:40:39.926Z","dateUpdated":"2026-08-17T05:43:53.927Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:22:14","lastModifiedDate":"2026-08-17 06:19:08","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"72412","Ordinal":"1","Title":"s390/mm: Fix handling of _PAGE_UNUSED pte bit","CVE":"CVE-2026-72412","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"72412","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Fix handling of _PAGE_UNUSED pte bit\n\nThe _PAGE_UNUSED softbit should not really be lying around. Its sole\npurpose is to signal to try_to_unmap_one() and try_to_migrate_one()\nthat the page can be discarded instead of being moved / swapped.\n\nKVM has no way to know why a page is being unmapped, so it sets the bit\non userspace ptes corresponding to unused guest pages every time they\nget unmapped. KVM has no reasonable way to clear the bit once the page\nis in use again.\n\nWhile set_ptes() checks and clears the bit, other paths that set new\nptes did not. This led to used pages being thrown out as if they were\nunused, causing guest corruption.\n\nFix the issue by clearing the _PAGE_UNUSED bit for present ptes in\nset_pte(), i.e. whenever a present pte is getting set. The check in\nset_ptes() is then redundant and can be removed.\n\nAlso fix gmap_helper_try_set_pte_unused() to only set the bit if the\npte is present; the _PAGE_UNUSED bit is only defined for present ptes\nand thus should not be set for non-present ptes.","Type":"Description","Title":"s390/mm: Fix handling of _PAGE_UNUSED pte bit"}]}}}