CVE-2026-43258 (GCVE-0-2026-43258)
Vulnerability from cvelistv5
Published
2026-05-06 11:28
Modified
2026-08-05 12:26
Summary
In the Linux kernel, the following vulnerability has been resolved: alpha: fix user-space corruption during memory compaction Alpha systems can suffer sporadic user-space crashes and heap corruption when memory compaction is enabled. Symptoms include SIGSEGV, glibc allocator failures (e.g. "unaligned tcache chunk"), and compiler internal errors. The failures disappear when compaction is disabled or when using global TLB invalidation. The root cause is insufficient TLB shootdown during page migration. Alpha relies on ASN-based MM context rollover for instruction cache coherency, but this alone is not sufficient to prevent stale data or instruction translations from surviving migration. Fix this by introducing a migration-specific helper that combines: - MM context invalidation (ASN rollover), - immediate per-CPU TLB invalidation (TBI), - synchronous cross-CPU shootdown when required. The helper is used only by migration/compaction paths to avoid changing global TLB semantics. Additionally, update flush_tlb_other(), pte_clear(), to use READ_ONCE()/WRITE_ONCE() for correct SMP memory ordering. This fixes observed crashes on both UP and SMP Alpha systems.
Impacted products
Vendor Product Version
Linux Linux Version: a48d07afdf18212de22b959715b16793c5a6e57a
Version: a48d07afdf18212de22b959715b16793c5a6e57a
Version: a48d07afdf18212de22b959715b16793c5a6e57a
Version: a48d07afdf18212de22b959715b16793c5a6e57a
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "arch/alpha/include/asm/pgtable.h",
            "arch/alpha/include/asm/tlbflush.h",
            "arch/alpha/mm/Makefile",
            "arch/alpha/mm/tlbflush.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "d4ca6ca2c6f5a1d19d9014c5b36d96637846b5d6",
              "status": "affected",
              "version": "a48d07afdf18212de22b959715b16793c5a6e57a",
              "versionType": "git"
            },
            {
              "lessThan": "03e42b5f7ad4c2c3db8bd384bab7990d5d53c90f",
              "status": "affected",
              "version": "a48d07afdf18212de22b959715b16793c5a6e57a",
              "versionType": "git"
            },
            {
              "lessThan": "bab8d762a8dbb816b10011e13b87d1bca91e5f77",
              "status": "affected",
              "version": "a48d07afdf18212de22b959715b16793c5a6e57a",
              "versionType": "git"
            },
            {
              "lessThan": "dd5712f3379cfe760267cdd28ff957d9ab4e51c7",
              "status": "affected",
              "version": "a48d07afdf18212de22b959715b16793c5a6e57a",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "arch/alpha/include/asm/pgtable.h",
            "arch/alpha/include/asm/tlbflush.h",
            "arch/alpha/mm/Makefile",
            "arch/alpha/mm/tlbflush.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.16"
            },
            {
              "lessThan": "2.6.16",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.75",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.16",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.6",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.75",
                  "versionStartIncluding": "2.6.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.16",
                  "versionStartIncluding": "2.6.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.6",
                  "versionStartIncluding": "2.6.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "2.6.16",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nalpha: fix user-space corruption during memory compaction\n\nAlpha systems can suffer sporadic user-space crashes and heap\ncorruption when memory compaction is enabled.\n\nSymptoms include SIGSEGV, glibc allocator failures (e.g. \"unaligned\ntcache chunk\"), and compiler internal errors. The failures disappear\nwhen compaction is disabled or when using global TLB invalidation.\n\nThe root cause is insufficient TLB shootdown during page migration.\nAlpha relies on ASN-based MM context rollover for instruction cache\ncoherency, but this alone is not sufficient to prevent stale data or\ninstruction translations from surviving migration.\n\nFix this by introducing a migration-specific helper that combines:\n  - MM context invalidation (ASN rollover),\n  - immediate per-CPU TLB invalidation (TBI),\n  - synchronous cross-CPU shootdown when required.\n\nThe helper is used only by migration/compaction paths to avoid changing\nglobal TLB semantics.\n\nAdditionally, update flush_tlb_other(), pte_clear(), to use\nREAD_ONCE()/WRITE_ONCE() for correct SMP memory ordering.\n\nThis fixes observed crashes on both UP and SMP Alpha systems."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable path is reached locally through memory migration/compaction, including page faults/high-order or THP allocation pressure and same-process migration interfaces, not through a network or physical interface.\nAC:L - An unprivileged attacker can repeatedly create memory pressure and migratable mappings to drive compaction/migration; no uncontrollable race or victim timing is required for triggering the stale TLB condition.\nPR:L - A basic local user can allocate memory, fault pages, use madvise/THP-related behavior, and migrate its own pages; privileged manual compact_memory access is not required.\nUI:N - Once the attacker has local execution, no separate victim action is needed to trigger compaction or access the stale mapping.\nS:U - The bug is in kernel memory-management enforcement for local processes and does not cross a separate security authority such as a hypervisor or sandbox boundary.\nC:H - Stale user TLB entries can continue to reference a physical page after migration, allowing reads from a page after it is freed and potentially reallocated to page cache or another process.\nI:H - The same stale writable mapping can corrupt the reallocated physical page, making cross-process/page-cache corruption and code/data modification defensible.\nA:H - The issue is documented to cause SIGSEGVs, glibc heap corruption, compiler crashes, and other repeated user-space corruption during compaction."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:26:56.947Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d4ca6ca2c6f5a1d19d9014c5b36d96637846b5d6"
        },
        {
          "url": "https://git.kernel.org/stable/c/03e42b5f7ad4c2c3db8bd384bab7990d5d53c90f"
        },
        {
          "url": "https://git.kernel.org/stable/c/bab8d762a8dbb816b10011e13b87d1bca91e5f77"
        },
        {
          "url": "https://git.kernel.org/stable/c/dd5712f3379cfe760267cdd28ff957d9ab4e51c7"
        }
      ],
      "title": "alpha: fix user-space corruption during memory compaction",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-43258",
    "datePublished": "2026-05-06T11:28:46.536Z",
    "dateReserved": "2026-05-01T14:12:55.997Z",
    "dateUpdated": "2026-08-05T12:26:56.947Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…