CVE-2026-90303 PUBLISHED

ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults

When CONFIG_DEBUG_USER=y, and cmdline "user_debug=31" is set, a user fault may trigger show_pte() without any lock. If another thread in the same process concurrently calls munmap(), the page table pages may be freed while show_pte() is still traversing them, causing a use-after-free in show_pte().

If CONFIG_ARM_LPAE=y, this may cause a kernel panic if the pages table of PMD are freed when show_pte() is running.

Acquire mmap_write_lock() around show_pte() for user faults to fix the contention.

For user faults, additionally restrict that show_pte() is called only when the addr is a user-space address (addr < TASK_SIZE). This is because the lock of tsk->mm only protects the virtual memory of user address space, furthermore, dumping the page tables of a kernel-space address for user faults is unnecessary and may have security implications.

Keep everything unchanged for kernel faults, because the kernel is already in the "oops" state, acquiring a lock may risk a deadlock.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 6d021b724481fbb908eb29384898deb9f00dfe70 to ab14f07952adfe735d86a53518f8cd576dfd5892 (excl.)
  • affected from 6d021b724481fbb908eb29384898deb9f00dfe70 to 07e4d5380f2a844ab7a1b440dde350caf561cbb0 (excl.)
  • affected from 6d021b724481fbb908eb29384898deb9f00dfe70 to 2a14d7797a49a47bccd1a9327fd69da838dcb0dd (excl.)
  • affected from 6d021b724481fbb908eb29384898deb9f00dfe70 to 63e3c958a602d0896a101a897c2361878c266ca7 (excl.)
  • affected from 6d021b724481fbb908eb29384898deb9f00dfe70 to 59bbf86d0ff9373bfa033ca123c1e924f09f1eba (excl.)
  • affected from 6d021b724481fbb908eb29384898deb9f00dfe70 to c71f9a56520b419e55d173052629f2324deb5549 (excl.)
  • affected from 6d021b724481fbb908eb29384898deb9f00dfe70 to 720408d98d9fb3c91a12090436734c8c61f04545 (excl.)
  • affected from 6d021b724481fbb908eb29384898deb9f00dfe70 to 1039bffd6ae9c75b42b7d148d6c1106134107b66 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.0 is affected
  • unaffected from 0 to 4.0 (excl.)
  • unaffected from 5.10.270 to 5.10.* (incl.)
  • unaffected from 5.15.221 to 5.15.* (incl.)
  • unaffected from 6.1.188 to 6.1.* (incl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References