Linux maintainers patched an x86 kernel defect that can silently discard rewritten user-space data under a specific combination of transparent huge pages, cgroup memory limits, MADV_FREE, and heavy memory-reclaim pressure. The flaw, present since Linux 6.6, occurs when pmd_modify() fails to retain the hardware dirty bit during certain memory-protection or NUMA-placement changes; reclaim can then treat live pages as disposable and return zero-filled data instead.
The issue has caused production data loss, including reports from users of the Polars data analytics library. A one-line correction preserving the dirty state was committed on September 9 and merged via the x86 urgent tree after Linux 7.3-rc3, with backports planned for supported stable kernel series. Available reporting indicates an integrity defect rather than malicious exploitation; organizations running affected kernels should prioritize stable updates, particularly on workloads using transparent huge pages and memory-constrained cgroups.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The x86/urgent merge path brought the correction into Linux mainline following the Linux 7.3-rc3 release. The fix was also marked for backporting to supported stable kernel series.
A one-line fix preserving the hardware dirty value in pmd_modify() was committed to prevent reclaim from discarding rewritten huge-page memory as clean.
The issue was reported with a small C proof of concept after being linked to production data loss, including Polars users receiving zero-filled memory in place of rewritten data. The failure required MADV_FREE, PMD-mapped transparent huge pages, subsequent writes and page-table changes, and memory-reclaim pressure.
A defect in the x86 pmd_modify() helper was introduced, allowing PMD page-table changes to lose the hardware dirty bit needed for correct transparent-huge-page reclaim decisions. The bug affected kernel releases beginning with Linux 6.6.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.