CVE-2026-23375General(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: mm: thp: deny THP for files on anonymous inodes file_thp_enabled() incorrectly allows THP for files on anonymous inodes (e.g. guest_memfd and secretmem). These files are created via alloc_file_pseudo(), which does not call get_write_access() and leaves inode->i_writecount at 0. Combined with S_ISREG(inode->i_mode) being true, they appear as read-only regular files when CONFIG_READ_ONLY_THP_FOR_FS is enabled, making them eligible for THP collapse. Anonymous inodes can never pass the inode_is_open_for_write() check since their i_writecount is never incremented through the normal VFS open path. The right thing to do is to exclude them from THP eligibility altogether, since CONFIG_READ_ONLY_THP_FOR_FS was designed for real filesystem files (e.g. shared libraries), not for pseudo-filesystem inodes. For guest_memfd, this allows khugepaged and MADV_COLLAPSE to create large folios in the page cache via the collapse path, but the guest_memfd fault handler does not support large folios. This triggers WARN_ON_ONCE(folio_test_large(folio)) in kvm_gmem_fault_user_mapping(). For secretmem, collapse_file() tries to copy page contents through the direct map, but secretmem pages are removed from the direct map. This can result in a kernel crash: BUG: unable to handle page fault for address: ffff88810284d000 RIP: 0010:memcpy_orig+0x16/0x130 Call Trace: collapse_file hpage_collapse_scan_file madvise_collapse Secretmem is not affected by the crash on upstream as the memory failure recovery handles the failed copy gracefully, but it still triggers confusing false memory failure reports: Memory failure: 0x106d96f: recovery action for clean unevictable LRU page: Recovered Check IS_ANON_FILE(inode) in file_thp_enabled() to deny THP for all anonymous inode files.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-30: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-30: 103-2503-30
Signal classification3 categories
General
133.3%
Patch
133.3%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-252
General1Patch1
2026-03-301
Disclosure1
Full discourse3 posts
  • 777@SteveAJ777
    Disclosure

    U might wanna check these out The "OpenWrt mDNS" Stack Overflow (CVE-2026-30871) This is the big one for today. A 9.8 Critical vulnerability was just disclosed affecting the mdns daemon on OpenWrt. •The Vulnerability: An attacker can send a specially crafted DNS packet (via UDP port 5353) that triggers a stack-based buffer overflow. •The Risk: Since mDNS is often enabled by default for "Easy Discovery" of devices on a local network, an attacker on your Wi-Fi (or a compromised device) could potentially gain full control of the router. The "NetScaler-Style" Memory Leak (CVE-2026-3055) While this specifically targets Citrix NetScaler, researchers today are reporting active "Reconnaissance" (probing) across the internet for similar memory-overread flaws in other gateway appliances. •This exploit allows unauthenticated attackers to "leak" sensitive data from the system's memory. Linux Kernel "Transparent Huge Pages" Flaw (CVE-2026-23375) Published just hours ago, this is a local privilege escalation flaw in the Linux kernel's memory management. •The Risk: It involves a logic flaw in how the kernel handles "Secret Memory" (secretmem). A local user could potentially crash the kernel or elevate their privileges.

    Post summary

    The text announces three CVEs, detailing their technical aspects and severity, but does not provide evidence of PoC, exploit code, active exploitation, patches, or false positives.

    0000083
    190 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-23375 Linux Kernel Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23375

    Post summary

    Only a CVE reference and a link to a vulnerability page are provided, with no additional context or technical details.

    0000043
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23375 In the Linux kernel, the following vulnerability has been resolved: mm: thp: deny THP for files on anonymous inodes file_thp_enabled() incorrectly allows THP for fi… https://www.cve.org/CVERecord?id=CVE-2026-23375

    Post summary

    The entry announces that CVE-2026-23375 has been resolved, implying a patch or fix exists, but no detailed vulnerability, PoC, or exploitation information is shared.

    0000082
    56.8K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.8--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more