Database/Kernel, userspace & hypervisor
Linux kernel mm: mincore/MADV_PAGEOUT ownership checks use the wrong idmap on idmapped mounts
Impact
The ownership check that gates the page-cache side-channel protection in mincore() and madvise(MADV_PAGEOUT) was evaluated against nop_mnt_idmap, so it ignored the mount's idmap entirely. On idmapped mounts, which is how container runtimes and user-namespace pods present shared images and volumes, that check decides against the on-disk owner rather than the translated one, so the policy the kernel enforces is not the policy it intends. Upstream describes the practical effect as usually benign, because the fallback file_permission(MAY_WRITE) does use the correct idmap and normally succeeds; the visible edge case is a mode-0444 file where neither check passes. The record shows no demonstrated cross-tenant page-cache leak, and the issue was found by code inspection rather than in the wild, so treat this as an isolation-semantics correctness fix on multi-tenant nodes, not an urgent one.
Who can reach it
Local unprivileged process calling mincore() or madvise(MADV_PAGEOUT) on a file reached through an idmapped mount, for example a tenant process inside a user-namespaced container. No authentication beyond having a shell or workload on the node.
What to do
Pick up the fixed stable kernel (commits at git.kernel.org) and reboot each node; the change is in mm, so there is no daemon-restart or live-patch path. Given the low practical impact, fold it into the next scheduled kernel rotation rather than a dedicated drain.
References
Related entries
- Linux kernel x86/mm: vmemmap pages freed as page tables leak memory on memory hot-removeCVE-2026-64302 · Linux kernel x86/mm (vmemmap page freeing on memory hot-remove)Medium
- Linux kernel CTR_DRBG: generate can report success while leaving the output buffer uninitializedCVE-2026-64306 · Linux kernel crypto DRBG (drbg_ctr_generate)Medium
- Linux kernel ccp: /dev/sev ioctls re-run SEV platform init and can crash a host running VMsCVE-2026-64307 · Linux kernel ccp/PSP driver (/dev/sev ioctls re-running SEV/SNP platform init)Medium
- Linux kernel chacha20poly1305 template: missing argument check dereferences an error pointerCVE-2026-64314 · Linux kernel crypto chacha20poly1305 template (chachapoly_create)Medium
- Linux nvmet-rdma: device reference leaks whenever a queue connect is rejected as busyCVE-2026-64321 · Linux kernel nvmet-rdma (device refcount on queue connect)Medium
- Linux kernel BPF verifier: map-in-map lookup nullness elided using the wrong max_entriesCVE-2026-64353 · Linux kernel BPF verifier (ARRAY_OF_MAPS with BPF_F_INNER_MAP inner arrays)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.