{"api_version":"1","generated_at":"2026-10-04T10:14:33+00:00","cve":"CVE-2026-93230","urls":{"html":"https://cve.report/CVE-2026-93230","api":"https://cve.report/api/cve/CVE-2026-93230.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93230","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93230"},"summary":{"title":"mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier\n\nGigantic bootmem HugeTLB pages are currently initialized from\nhugetlb_init(), but page_alloc_init_late() runs earlier and walks\npageblocks to determine zone contiguity.\n\nIf a bootmem HugeTLB region is marked noinit, set_zone_contiguous() can\nobserve still-uninitialized struct pages through\n__pageblock_pfn_to_page().  This may not trigger an immediate failure, but\nit can make set_zone_contiguous() compute the wrong zone contiguity state.\nIf extra poisoned-page checks are added in this path, such as\nPF_POISONED_CHECK() in page_zone_id(), it can also trigger an early boot\npanic.\n\nInitialize gigantic bootmem HugeTLB struct pages from\npage_alloc_init_late(), before zone contiguity is evaluated, so later page\nallocator setup only sees valid struct page state.  This also makes the\ninitialization order more natural, as struct pages should be initialized\nbefore later code inspects them.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-24 16:17:18","updated_at":"2026-09-24 16:17:18"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/09505232eced5f1c42902d8f28740f070c3fc6dc","name":"https://git.kernel.org/stable/c/09505232eced5f1c42902d8f28740f070c3fc6dc","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b1b7c045e808c761b1cc8c19b3040fadedda3fef","name":"https://git.kernel.org/stable/c/b1b7c045e808c761b1cc8c19b3040fadedda3fef","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/29968bc7aefb3cf1e72aa7c5f52697a6b0527094","name":"https://git.kernel.org/stable/c/29968bc7aefb3cf1e72aa7c5f52697a6b0527094","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93230","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93230","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected fde1c4ecf91640e5a95ec36b71ec2e8ec379ce40 09505232eced5f1c42902d8f28740f070c3fc6dc git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected fde1c4ecf91640e5a95ec36b71ec2e8ec379ce40 29968bc7aefb3cf1e72aa7c5f52697a6b0527094 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected fde1c4ecf91640e5a95ec36b71ec2e8ec379ce40 b1b7c045e808c761b1cc8c19b3040fadedda3fef git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.7","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.7 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.4 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["include/linux/hugetlb.h","mm/hugetlb.c","mm/mm_init.c","mm/sparse-vmemmap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"09505232eced5f1c42902d8f28740f070c3fc6dc","status":"affected","version":"fde1c4ecf91640e5a95ec36b71ec2e8ec379ce40","versionType":"git"},{"lessThan":"29968bc7aefb3cf1e72aa7c5f52697a6b0527094","status":"affected","version":"fde1c4ecf91640e5a95ec36b71ec2e8ec379ce40","versionType":"git"},{"lessThan":"b1b7c045e808c761b1cc8c19b3040fadedda3fef","status":"affected","version":"fde1c4ecf91640e5a95ec36b71ec2e8ec379ce40","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["include/linux/hugetlb.h","mm/hugetlb.c","mm/mm_init.c","mm/sparse-vmemmap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.7"},{"lessThan":"6.7","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"6.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.4","versionStartIncluding":"6.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.7","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier\n\nGigantic bootmem HugeTLB pages are currently initialized from\nhugetlb_init(), but page_alloc_init_late() runs earlier and walks\npageblocks to determine zone contiguity.\n\nIf a bootmem HugeTLB region is marked noinit, set_zone_contiguous() can\nobserve still-uninitialized struct pages through\n__pageblock_pfn_to_page().  This may not trigger an immediate failure, but\nit can make set_zone_contiguous() compute the wrong zone contiguity state.\nIf extra poisoned-page checks are added in this path, such as\nPF_POISONED_CHECK() in page_zone_id(), it can also trigger an early boot\npanic.\n\nInitialize gigantic bootmem HugeTLB struct pages from\npage_alloc_init_late(), before zone contiguity is evaluated, so later page\nallocator setup only sees valid struct page state.  This also makes the\ninitialization order more natural, as struct pages should be initialized\nbefore later code inspects them."}],"providerMetadata":{"dateUpdated":"2026-09-24T15:29:16.067Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/09505232eced5f1c42902d8f28740f070c3fc6dc"},{"url":"https://git.kernel.org/stable/c/29968bc7aefb3cf1e72aa7c5f52697a6b0527094"},{"url":"https://git.kernel.org/stable/c/b1b7c045e808c761b1cc8c19b3040fadedda3fef"}],"title":"mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93230","datePublished":"2026-09-24T15:29:16.067Z","dateReserved":"2026-09-17T16:02:15.094Z","dateUpdated":"2026-09-24T15:29:16.067Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 16:17:18","lastModifiedDate":"2026-09-24 16:17:18","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93230","Ordinal":"1","Title":"mm/hugetlb: initialize gigantic bootmem hugepage struct pages ea","CVE":"CVE-2026-93230","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93230","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier\n\nGigantic bootmem HugeTLB pages are currently initialized from\nhugetlb_init(), but page_alloc_init_late() runs earlier and walks\npageblocks to determine zone contiguity.\n\nIf a bootmem HugeTLB region is marked noinit, set_zone_contiguous() can\nobserve still-uninitialized struct pages through\n__pageblock_pfn_to_page().  This may not trigger an immediate failure, but\nit can make set_zone_contiguous() compute the wrong zone contiguity state.\nIf extra poisoned-page checks are added in this path, such as\nPF_POISONED_CHECK() in page_zone_id(), it can also trigger an early boot\npanic.\n\nInitialize gigantic bootmem HugeTLB struct pages from\npage_alloc_init_late(), before zone contiguity is evaluated, so later page\nallocator setup only sees valid struct page state.  This also makes the\ninitialization order more natural, as struct pages should be initialized\nbefore later code inspects them.","Type":"Description","Title":"mm/hugetlb: initialize gigantic bootmem hugepage struct pages ea"}]}}}