{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.187-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.105-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.107-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  mm/hugetlb: fix list corruption in allocate_file_region_entries()  allocate_file_region_entries() tops up resv-\u003eregion_cache with freshly allocated file_region descriptors.  The allocation uses GFP_KERNEL, so resv-\u003elock is dropped around it: the new entries are gathered on a stack-local list head, allocated_regions, and spliced into resv-\u003eregion_cache once the lock is re-acquired.  The splice used list_splice(), which moves the entries but does not re-initialize the source head, so allocated_regions is left pointing at an entry that now lives on resv-\u003eregion_cache.  The top-up runs in a while loop that re-checks the cache deficit after re-acquiring the lock.  For a shared mapping the resv_map is shared by every mapper of the hugetlbfs inode, so a concurrent region_chg()/region_add()/region_del() on the same resv_map can consume cache entries during the unlocked window and force a second iteration.  That iteration calls list_add() on the stale head and corrupts the list; with CONFIG_DEBUG_LIST the __list_add_valid() check trips:    list_add corruption. next-\u003eprev should be prev (ffffc900011ff7f8),   but was ffff88814c281460. (next=ffff88814c545640).   kernel BUG at lib/list_debug.c:31!    allocate_file_region_entries+0x191/0x420    region_chg+0x267/0x300    hugetlb_reserve_pages+0x387/0xc80    hugetlbfs_file_mmap+0x2ce/0x3f0    mmap_region+0x1348/0x1a80    do_mmap+0x85e/0xb90    vm_mmap_pgoff+0x18c/0x330    ksys_mmap_pgoff+0x2a1/0x3e0    do_syscall_64+0xd7/0x420  Without CONFIG_DEBUG_LIST the bad list_add() silently links a kernel-stack address into resv-\u003eregion_cache, leading to later use-after-free.  This was observed as a real host panic on a dense KVM host where a QEMU guest-RAM hugetlbfs file was mapped MAP_SHARED by both QEMU and a separate SPDK/DPDK vhost-user target, generating concurrent region_* traffic on one shared resv_map.  Use list_splice_init() so the source head is re-initialized empty after each splice, making the retry loop safe.",
  "id": "DEBIAN-CVE-2026-74518",
  "modified": "2026-09-19T21:47:32.729710347Z",
  "published": "2026-08-15T13:17:56.967Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-74518"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-74518"
  ]
}