Answer in brief
CVE-2026-98224 records a Unknown severity vulnerability in mm/vma: correctly unaccount on mmap_prepare() failure. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c84bf6dd2b836b49bb2662668ff1692350d28236 <fb5400bff669c8bad3d4ec09287d9b461e89e5f1 || >=c84bf6dd2b836b49bb2662668ff1692350d28236 <8fdc521d438fbf0d22c13d51d55d5dd82d7202b2 || >=c84bf6dd2b836b49bb2662668ff1692350d28236 <6cc27d82196385fe06853319f74312a7d8019726 | fb5400bff669c8bad3d4ec09287d9b461e89e5f1, 8fdc521d438fbf0d22c13d51d55d5dd82d7202b2, 6cc27d82196385fe06853319f74312a7d8019726 |
| Linux/Linuxgeneric | 6.16 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: mm/vma: correctly unaccount on mmap_prepare() failure __mmap_setup() accounts memory for relevant mappings via: security_vm_enough_memory_mm() -> __vm_enough_memory() -> vm_acct_memory() If __mmap_setup() fails, this indicates that this accounting did not take place, and thus it's appropriate for __mmap_region() to jump to abort_munmap. However if call_mmap_prepare() fails, it also jumps there and any accounted memory is not correctly unaccounted. Fix this by handling each error separately.
Quoted source text, attributed separately from HOL analysis.