CVE-2026-89755 is a vulnerability in Linux Kernel
Published on September 11, 2026
mm/migrate_device: clear stale mapping after freeing swapcache
In the Linux kernel, the following vulnerability has been resolved:
mm/migrate_device: clear stale mapping after freeing swapcache
__migrate_device_pages() reads the folio mapping before calling
folio_free_swap(). When folio_free_swap() succeeds, the folio is removed
from the swap cache, but the saved mapping still points to swap_space.
Passing the stale mapping to folio_migrate_mapping() makes it use the
mapped-folio path for a folio that is no longer in swapcache. It can then
operate on swap_space.i_pages with invalid reference accounting,
eventually triggering a folio reference count BUG.
After a successful split, nr still contains the number of pages in the
original large folio, although each resulting page is now a separate
order-0 folio. Reset nr to 1 so each split folio is processed separately,
including its own swapcache removal and mapping lookup.
Refresh the saved mapping after folio_free_swap() so the current folio
state is used during migration.
Products Associated with CVE-2026-89755
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version df263d9a7dffee94ca5391120ee3b0587efa07f1 and below 8ffedc6573a665cdc31ebe47eae7b32b78d0df83 is affected.
- Version df263d9a7dffee94ca5391120ee3b0587efa07f1 and below 34a00895d032a414830d41106a09329ae6c251b6 is affected.
- Version 6.6 is affected.
- Before 6.6 is unaffected.
- Version 7.2.4, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.