HomeDefectsLIN1023-34752
Fixed

LIN1023-34752 : Security Advisory - linux - CVE-2026-89755

Created: Oct 7, 2026    Updated: Oct 8, 2026
Resolved Date: Oct 7, 2026
Found In Version: 10.23.30.2
Fix Version: 10.23.30.8
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  mm/migrate_device: clear stale mapping after freeing swapcache  __migrate_device_pages() reads the folio mapping before calling folio_free_swap().  When folio_free_swap() succeeds, the folio is removed from the swap cache, but the saved mapping still points to swap_space.  Passing the stale mapping to folio_migrate_mapping() makes it use the mapped-folio path for a folio that is no longer in swapcache.  It can then operate on swap_space.i_pages with invalid reference accounting, eventually triggering a folio reference count BUG.  After a successful split, nr still contains the number of pages in the original large folio, although each resulting page is now a separate order-0 folio.  Reset nr to 1 so each split folio is processed separately, including its own swapcache removal and mapping lookup.  Refresh the saved mapping after folio_free_swap() so the current folio state is used during migration.
Data source: kernel.org (416baaa9-dc9f-4396-8d5f-8c081fb06d67)