CVE-2026-98224

medium

Description

In the Linux kernel, the following vulnerability has been resolved: mm/vma: correctly unaccount on mmap_prepare() failure __mmap_setup() accounts memory for relevant mappings via: security_vm_enough_memory_mm() -> __vm_enough_memory() -> vm_acct_memory() If __mmap_setup() fails, this indicates that this accounting did not take place, and thus it's appropriate for __mmap_region() to jump to abort_munmap. However if call_mmap_prepare() fails, it also jumps there and any accounted memory is not correctly unaccounted. Fix this by handling each error separately.

References

https://git.kernel.org/stable/c/fb5400bff669c8bad3d4ec09287d9b461e89e5f1

https://git.kernel.org/stable/c/8fdc521d438fbf0d22c13d51d55d5dd82d7202b2

https://git.kernel.org/stable/c/6cc27d82196385fe06853319f74312a7d8019726

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93152

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00173