← All Advisories

CVE-2026-97525

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97525

Key Details

CVECVE-2026-97525
CVSS Score / Version8.2 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

x86/mm/pat: Allocate split page tables as kernel page tables

A PTE is allocated directly without going through the standard page table

allocation routines (such as pte_alloc_one_kernel()) when the CPA code

splits a large page (__split_large_page()).

This means the page table constructor is never called nor is the page table

marked as a kernel page table.

The former results in the folio associated with the page table not being

marked as a page table (__pagetable_ctor() is never called thus neither is

__folio_set_pgtable()) nor are statistics updated to reflect

it (lruvec_stat_add_folio() is never called).

The latter issue of failing to mark the page table as a kernel page

table (ptdesc_set_kernel() is never called) is far more problematic.

Since commit:

5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables")

kernel page table freeing has been batched and since the

subsequent commit:

e37d5a2d60a3 ("iommu/sva: invalidate stale IOTLB entries for kernel address space")

IOTLB cache entries for kernel page tables have been invalidated upon

being freed.

Since split page tables are freed without this invalidation, the IOTLB

can contain stale entries for them.

Resolve the issue by using the ordinary PTE allocation API at split time.

This results in these kernel page tables invoking a page table constructor,

and thus requires a page table destructor.

Destructors are not always present, like for early allocated direct map

page tables). Conditionally call pagetable_dtor_free() if the PG_table

folio flag for the ptdesc is set, otherwise we free the page table via

pagetable_free().

Regardless of which path is taken page tables marked as kernel page tables,

which now includes split page tables, take the correct route through

pagetable_free_kernel().

There is a user-visible side effect in that split page tables will appear

in nr_page_table_pages in /proc/vmstat (as do other kernel page tables

allocated after early boot), however this is a positive change.

This issue started being markedly problematic after commit:

5ba2f0a15564 ("mm: introduce deferred freeing for kernel page tables")

so choose this as the Fixes target.

[ dhansen: rephrase in imperative mood ] (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97525
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97525