CVE-2026-23097 is a Linux kernel deadlock vulnerability caused by incorrect lock ordering during migration of hugetlb file-backed folios. The migration path acquires folio_lock in unmap_and_move_huge_page() before attempting to acquire the i_mmap_rwsem read lock through remove_migration_ptes(). Concurrent hugetlbfs hole-punching can hold the i_mmap_rwsem write lock while waiting for folio_lock, creating an ABBA deadlock. The vulnerability can hang tasks indefinitely and potentially cause system-wide stalls. The correction extends the existing i_mmap lock scope to cover remove_migration_ptes(), restoring consistent lock ordering for file-backed hugetlb folios.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel lock-ordering flaw in hugetlb file-folio migration can cause a deadlock when migration and hole-punching operations acquire folio_lock and i_mmap_rwsem in opposite orders. The vulnerability affects availability and has a CVSS v3 base score of 5.5, with local access and low privileges required. The fix expands the existing i_mmap_lock scope to cover remove_migration_ptes() calls. The plugin recommends updating sys-kernel/csql-kernel-6_1 and related packages to version 18613.534.2 or later.
A Linux kernel lock-ordering flaw in hugetlb file-folio migration can cause a deadlock when migration and hugetlbfs hole-punching operations acquire locks in opposite orders. The vulnerability affects availability and has a CVSS v3 base score of 5.5, with local access and low privileges required. The fix expands the existing i_mmap_lock scope to cover remove_migration_ptes().
A Linux kernel denial-of-service vulnerability caused by a deadlock during hugetlb folio migration. It is addressed in CIQ advisory CRLSA-2026_3488 for Rocky Linux 9. The notice lists a CVSS v3 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.
A vulnerability addressed by the referenced CentOS/TuxCare security advisory.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.