{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-43258", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-05-01T14:12:55.997Z", "datePublished": "2026-05-06T11:28:46.536Z", "dateUpdated": "2026-08-05T12:26:56.947Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:26:56.947Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nalpha: fix user-space corruption during memory compaction\n\nAlpha systems can suffer sporadic user-space crashes and heap\ncorruption when memory compaction is enabled.\n\nSymptoms include SIGSEGV, glibc allocator failures (e.g. \"unaligned\ntcache chunk\"), and compiler internal errors. The failures disappear\nwhen compaction is disabled or when using global TLB invalidation.\n\nThe root cause is insufficient TLB shootdown during page migration.\nAlpha relies on ASN-based MM context rollover for instruction cache\ncoherency, but this alone is not sufficient to prevent stale data or\ninstruction translations from surviving migration.\n\nFix this by introducing a migration-specific helper that combines:\n - MM context invalidation (ASN rollover),\n - immediate per-CPU TLB invalidation (TBI),\n - synchronous cross-CPU shootdown when required.\n\nThe helper is used only by migration/compaction paths to avoid changing\nglobal TLB semantics.\n\nAdditionally, update flush_tlb_other(), pte_clear(), to use\nREAD_ONCE()/WRITE_ONCE() for correct SMP memory ordering.\n\nThis fixes observed crashes on both UP and SMP Alpha systems." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable path is reached locally through memory migration/compaction, including page faults/high-order or THP allocation pressure and same-process migration interfaces, not through a network or physical interface.\nAC:L - An unprivileged attacker can repeatedly create memory pressure and migratable mappings to drive compaction/migration; no uncontrollable race or victim timing is required for triggering the stale TLB condition.\nPR:L - A basic local user can allocate memory, fault pages, use madvise/THP-related behavior, and migrate its own pages; privileged manual compact_memory access is not required.\nUI:N - Once the attacker has local execution, no separate victim action is needed to trigger compaction or access the stale mapping.\nS:U - The bug is in kernel memory-management enforcement for local processes and does not cross a separate security authority such as a hypervisor or sandbox boundary.\nC:H - Stale user TLB entries can continue to reference a physical page after migration, allowing reads from a page after it is freed and potentially reallocated to page cache or another process.\nI:H - The same stale writable mapping can corrupt the reallocated physical page, making cross-process/page-cache corruption and code/data modification defensible.\nA:H - The issue is documented to cause SIGSEGVs, glibc heap corruption, compiler crashes, and other repeated user-space corruption during compaction." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "arch/alpha/include/asm/pgtable.h", "arch/alpha/include/asm/tlbflush.h", "arch/alpha/mm/Makefile", "arch/alpha/mm/tlbflush.c" ], "versions": [ { "version": "a48d07afdf18212de22b959715b16793c5a6e57a", "lessThan": "d4ca6ca2c6f5a1d19d9014c5b36d96637846b5d6", "status": "affected", "versionType": "git" }, { "version": "a48d07afdf18212de22b959715b16793c5a6e57a", "lessThan": "03e42b5f7ad4c2c3db8bd384bab7990d5d53c90f", "status": "affected", "versionType": "git" }, { "version": "a48d07afdf18212de22b959715b16793c5a6e57a", "lessThan": "bab8d762a8dbb816b10011e13b87d1bca91e5f77", "status": "affected", "versionType": "git" }, { "version": "a48d07afdf18212de22b959715b16793c5a6e57a", "lessThan": "dd5712f3379cfe760267cdd28ff957d9ab4e51c7", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "arch/alpha/include/asm/pgtable.h", "arch/alpha/include/asm/tlbflush.h", "arch/alpha/mm/Makefile", "arch/alpha/mm/tlbflush.c" ], "versions": [ { "version": "2.6.16", "status": "affected" }, { "version": "0", "lessThan": "2.6.16", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.75", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.16", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.19.6", "lessThanOrEqual": "6.19.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.0", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.16", "versionEndExcluding": "6.12.75" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.16", "versionEndExcluding": "6.18.16" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.16", "versionEndExcluding": "6.19.6" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.16", "versionEndExcluding": "7.0" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/d4ca6ca2c6f5a1d19d9014c5b36d96637846b5d6" }, { "url": "https://git.kernel.org/stable/c/03e42b5f7ad4c2c3db8bd384bab7990d5d53c90f" }, { "url": "https://git.kernel.org/stable/c/bab8d762a8dbb816b10011e13b87d1bca91e5f77" }, { "url": "https://git.kernel.org/stable/c/dd5712f3379cfe760267cdd28ff957d9ab4e51c7" } ], "title": "alpha: fix user-space corruption during memory compaction", "x_generator": { "engine": "bippy-1.2.0" } } } }