ACK: [SRU][Q][PATCH 0/1] CVE-2026-31589
Hui Wang
hui.wang at canonical.com
Tue Jun 23 10:30:30 UTC 2026
Acked-by: Hui Wang <hui.wang at canonical.com>
On 6/23/26 11:43, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2026-31589
>
> [ Impact ]
>
> In folio_unmap_invalidate(), filemap_free_folio() could be called after the
> folio had already been removed from the mapping, at a point where the code no
> longer held a reference to or a lock on the mapping. Since the folio no longer
> pinned the mapping, the mapping could be freed concurrently, leading to a use-
> after-free when accessing mapping->a_ops. With a CVSS score of 9.8, this is
> remotely exploitable and can lead to memory corruption or privilege escalation.
>
> [ Fix ]
>
> questing: backported with AI-assisted adaptation
>
> [ Test Plan ]
>
> Boot tested.
>
> [ Where Problems Could Occur ]
>
> A regression in this memory management change could affect folio invalidation
> and the page cache writeback path, potentially causing incorrect free_folio()
> callback handling or leaks. Any error here would manifest in core mm behavior
> and could impact filesystem and I/O stability across the system.
>
More information about the kernel-team
mailing list