HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Antigravity CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
  4. CVE 2026 74672 mmvmalloc acquire initmm lock on huge vmap to
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Servers
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Back to active CVEs
Unknown severity · Source severity not reportedCVE-2026-74672

mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAFCVE-2026-74672

Answer in brief

CVE-2026-74672 records a Unknown severity vulnerability in mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.

Analysis pending evidence review

HOL Guard separates source facts from reviewed analysis. See the methodology.

Published Aug 22, 2026Updated Aug 23, 2026Source checked Oct 7, 2026First seen by HOL Aug 22, 2026Material review Aug 23, 2026
Upstream Advisory

Record context

Vulnerability class
Vulnerability
EPSS
Not reported
CWE IDs
Not reported
Source
CVE List V5
Source checked
Oct 7, 2026
References
6 linked sources
Open source record

Key facts

Risk
Unknown severitySource severity not reported
Exploitation
Not marked as known exploited
Affected software
3 mapped packages or products
Fix availability
Available

Why this deserves its current priority

A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.

Analysis status

Analysis pending evidence review

Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.

Affected scope and exposure questions

The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.

Mapped affected packages and fixed versions
PackageAffected rangeFixed version
Linux/Linuxgeneric>=b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <c5bf8cd148cfea948cfa3db71da427294b20db0f || >=b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <3cc26c8907db0f5d1ff8043b5851ee572e9b3c98 || >=b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <26444eb71465c9934d9d418ef69c43f61185329b || 31895cfd79564111cdd5a9f48c5d491ae26a238e || 9c7f7bdb1932f8c1e5f80d32c717184701afe701 || acdb4981644c8e31ccee294bdefff475c0cf587b || 0454e2fad9306961540ee7e84da47a8e345b7d22 || >=4.4.125 <4.5 || >=4.9.91 <4.10 || >=4.14.31 <4.15 || >=4.15.14 <4.16c5bf8cd148cfea948cfa3db71da427294b20db0f, 3cc26c8907db0f5d1ff8043b5851ee572e9b3c98, 26444eb71465c9934d9d418ef69c43f61185329b, 4.5, 4.10, 4.15, 4.16
Linux/Linuxgeneric4.16Not reported
Linux/Linuxgeneric>=b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <39c6772b56a6bbdd62794833f74232971d94d7c9 || >=b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <8d7f560f4b0482d469de962fbe4b59c37561052e || >=b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <7ac8a333dd41ba5e1b4e8c6edbc48b15446c5468 || >=b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <c5bf8cd148cfea948cfa3db71da427294b20db0f || >=b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <3cc26c8907db0f5d1ff8043b5851ee572e9b3c98 || >=b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e <26444eb71465c9934d9d418ef69c43f61185329b || 31895cfd79564111cdd5a9f48c5d491ae26a238e || 9c7f7bdb1932f8c1e5f80d32c717184701afe701 || acdb4981644c8e31ccee294bdefff475c0cf587b || 0454e2fad9306961540ee7e84da47a8e345b7d22 || >=4.4.125 <4.5 || >=4.9.91 <4.10 || >=4.14.31 <4.15 || >=4.15.14 <4.1639c6772b56a6bbdd62794833f74232971d94d7c9, 8d7f560f4b0482d469de962fbe4b59c37561052e, 7ac8a333dd41ba5e1b4e8c6edbc48b15446c5468, c5bf8cd148cfea948cfa3db71da427294b20db0f, 3cc26c8907db0f5d1ff8043b5851ee572e9b3c98, 26444eb71465c9934d9d418ef69c43f61185329b, 4.5, 4.10, 4.15, 4.16

Recommended response

  1. 1Check inventory. Check lockfiles and deployed manifests for Linux/Linux, Linux/Linux, Linux/Linux.
  2. 2Review the reported fix. Update Linux/Linux to c5bf8cd148cfea948cfa3db71da427294b20db0f; Linux/Linux to 39c6772b56a6bbdd62794833f74232971d94d7c9 if you use the affected versions. Test the change in a non-production environment first.

Evidence timeline and material changes

  1. Published upstream

    Aug 22, 2026

    Evidence: source:cvelist:source_dates:source-dates:record
  2. Source modified

    Aug 23, 2026

    Evidence: source:cvelist:source_dates:source-dates:record
  3. First seen by HOL

    Aug 22, 2026

Sources and claim methodology

  • Source referencegit.kernel.org
  • Source referencegit.kernel.org
  • Source referencegit.kernel.org
  • Source referencegit.kernel.org
  • Source referencegit.kernel.org
  • Source referencegit.kernel.org
Upstream source description

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF Patch series "mm: fix UAF caused by race between ptdump and vmap pgtable freeing", v6. Kernel page table walkers fall into two broad categories - those ranges where no exclusion is required via walk_kernel_page_table_range_lockless() and those where exclusion is required via walk_kernel_page_table_range() or walk_page_range_debug(). The former category is used only by arm64 arch code operating on ranges it both wholly owns and does not concurrently write. The latter category consists of kernel page table walkers operating on ranges that are wholly owned (but which need exclusion against concurrent writers). The lock used for exclusion is the mmap lock, and for kernel ranges this is the mmap lock on init_mm. ptdump is a special case being both the only user of walk_page_range_debug(), and the only case in which it walks ranges it does not own. This presents a problem, as page tables may be freed under ptdump. And indeed there is a use-after-free bug in the kernel as a result, which this series addresses. vmap promotes page tables to huge leaf entries where possible, freeing the lower page table when it does. It does this with no meaningful locks held against concurrent ptdump walks. As a result, use-after-free can currently occur. This series addresses the issue by having the vmap huge promotion logic acquire the mmap read lock while both setting the huge page table entry and freeing the prior leaf page table. The ptdump code already acquires the mmap write lock, so by doing so we ensure that the ptdump walker only ever observes either the huge page table entry or the existing page table entry, and nothing is freed underneath it. A mitigation for this issue was already applied for arm64 in commit fa93b45fd397 ("arm64: Enable vmalloc-huge with ptdump"), which this series has to deal with carefully. This mitigation resolves the issue by acquiring the mmap read lock on init_mm on vmap page table free if a ptdump is in progress. However the fix in this series would cause a deadlock if we were to simply apply it for arm64 without also reverting the change. This is because vmap may acquire the read lock before ptdump attempts to acquire the write lock, which then gets queued, and rwsem starvation rules mean that the (unacknowledged) nested mmap read lock in the arm64 code would also block, meaning the original read lock is never released and thus deadlock. This series works around this by #ifndef CONFIG_ARM64'ing the mmap read lock in vmap logic, then partially reverting commit fa93b45fd397 ("arm64: Enable vmalloc-huge with ptdump"), keeping the enablement of huge vmap support, and removing the ifdeffery with the partial revert patch. There are related issues that are also addressed in this series: * x86 page attribute logic, specifically Change Page Attributes (CPA), implements a feature whereby huge ranges can be collapsed into huge leaf entries. This can similarly cause a UAF when done in parallel with a ptdump walk, so similarly acquire the init_mm mmap lock to avoid this. * The CPA logic allows concurrent page table manipulation and CPA collapse, meaning the former risks accessing a page table the latter frees. Fix this by acquiring mmap write lock on init_mm across the whole CPA collapse operation and read lock on the page table manipulation. * x86 and arm64 permit walks of non-kernel mm's (both allowing efi mm walks, and in x86's case arbitrary mm's), so we ensure kernel mappings remain stable by locking the init_mm as well as the mm being walked. The ordering of patches is established for both strict dependencies (the arm64 partial revert in particular has to be done after the vmap changes) and logical ones (the non-kernel mm fix only makes sense once the vmap/CPA fixes are in place). This patch (of 3): Currently there is a nasty ra ---truncated---

Quoted source text, attributed separately from HOL analysis.

Related CVEs

  • Gitea OAuth2 refresh token grant accepts access tokensSame generic ecosystem
  • Langflow OSS is affected by multiple vulnerabilitiesSame generic ecosystem
  • Langflow OSS is affected by multiple vulnerabilitiesSame generic ecosystem
  • Langflow OSS is affected by multiple vulnerabilitiesSame generic ecosystem
  • Langflow OSS is affected by multiple vulnerabilitiesSame generic ecosystem
  • Langflow OSS is affected by multiple vulnerabilitiesSame generic ecosystem