CVE-2026-98224 PUBLISHED

mm/vma: correctly unaccount on mmap_prepare() failure

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

mm/vma: correctly unaccount on mmap_prepare() failure

__mmap_setup() accounts memory for relevant mappings via:

security_vm_enough_memory_mm() -> __vm_enough_memory() -> vm_acct_memory()

If __mmap_setup() fails, this indicates that this accounting did not take place, and thus it's appropriate for __mmap_region() to jump to abort_munmap.

However if call_mmap_prepare() fails, it also jumps there and any accounted memory is not correctly unaccounted.

Fix this by handling each error separately.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from c84bf6dd2b836b49bb2662668ff1692350d28236 to fb5400bff669c8bad3d4ec09287d9b461e89e5f1 (excl.)
  • affected from c84bf6dd2b836b49bb2662668ff1692350d28236 to 8fdc521d438fbf0d22c13d51d55d5dd82d7202b2 (excl.)
  • affected from c84bf6dd2b836b49bb2662668ff1692350d28236 to 6cc27d82196385fe06853319f74312a7d8019726 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.16 is affected
  • unaffected from 0 to 6.16 (excl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References