CVE-2026-43303
published 2026-05-08CVE-2026-43303: In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: clear page->private in free_pages_prepare() Several subsystems (slub, shmem…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
mm/page_alloc: clear page->private in free_pages_prepare()
Several subsystems (slub, shmem, ttm, etc.) use page->private but don't
clear it before freeing pages. When these pages are later allocated as
high-order pages and split via split_page(), tail pages retain stale
page->private values.
This causes a use-after-free in the swap subsystem. The swap code uses
page->private to track swap count continuations, assuming freshly
allocated pages have page->private == 0. When stale values are present,
swap_count_continued() incorrectly assumes the continuation list is valid
and iterates over uninitialized page->lru containing LIST_POISON values,
causing a crash:
KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]
RIP: 0010:__do_sys_swapoff+0x1151/0x1860
Fix this by clearing page->private in free_pages_prepare(), ensuring all
freed pages have clean state regardless of previous use.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 3b8000ae185cb068adbda5f966a3835053c85fd4 < e7790ab165713b79b1617ce659742ceb3a859d05 | e7790ab165713b79b1617ce659742ceb3a859d05 |
| linux | linux | >= 3b8000ae185cb068adbda5f966a3835053c85fd4 < 3edb8ebbf79b9016040e8f3421d723ae3d542b32 | 3edb8ebbf79b9016040e8f3421d723ae3d542b32 |
| linux | linux | >= 3b8000ae185cb068adbda5f966a3835053c85fd4 < f9719e32a67b4b00b3c9b133e8b5ffa72a26b67b | f9719e32a67b4b00b3c9b133e8b5ffa72a26b67b |
| linux | linux | >= 3b8000ae185cb068adbda5f966a3835053c85fd4 < 23b82b7a26182ad840ae67d390d7ec9771e8c00f | 23b82b7a26182ad840ae67d390d7ec9771e8c00f |
| linux | linux | >= 3b8000ae185cb068adbda5f966a3835053c85fd4 < d757c793853ec5483eb41ec2942c300b8fa720fb | d757c793853ec5483eb41ec2942c300b8fa720fb |
| linux | linux | >= 3b8000ae185cb068adbda5f966a3835053c85fd4 < ac1ea219590c09572ed5992dc233bbf7bb70fef9 | ac1ea219590c09572ed5992dc233bbf7bb70fef9 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 5.18.1 < 6.18.16 | 6.18.16 |
| linux | linux_kernel | >= 6.19 < 6.19.6 | 6.19.6 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.18.15/6.19.5 free_pages_prepare use after free
vuldb·2026-05-18·CVSS 7.8
CVE-2026-43303 [HIGH] Linux Kernel up to 6.18.15/6.19.5 free_pages_prepare use after free
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.15/6.19.5. Impacted is the function free_pages_prepare. The manipulation results in use after free.
This vulnerability is known as CVE-2026-43303. Access to the local network is required for this attack. No exploit is available.
You should upgrade the affected component.
GHSA
GHSA-6fh9-96ww-pvwq: In the Linux kernel, the following vulnerability has been resolved:
mm/page_alloc: clear page->private in free_pages_prepare()
Several subsystems (s
ghsa_unreviewed·2026-05-08
CVE-2026-43303 GHSA-6fh9-96ww-pvwq: In the Linux kernel, the following vulnerability has been resolved:
mm/page_alloc: clear page->private in free_pages_prepare()
Several subsystems (s
In the Linux kernel, the following vulnerability has been resolved:
mm/page_alloc: clear page->private in free_pages_prepare()
Several subsystems (slub, shmem, ttm, etc.) use page->private but don't
clear it before freeing pages. When these pages are later allocated as
high-order pages and split via split_page(), tail pages retain stale
page->private values.
This causes a use-after-free in the swap subsystem. The swap code uses
page->private to track swap count continuations, assuming freshly
allocated pages have page->private == 0. When stale values are present,
swap_count_continued() incorrectly assumes the continuation list is valid
and iterates over uninitialized page->lru containing LIST_POISON values,
causing a crash:
KASAN: maybe wild-memory-access in range [0xdead000000000100-0
Red Hat
kernel: mm/page_alloc: clear page->private in free_pages_prepare()
vendor_redhat·2026-05-08·CVSS 7.0
CVE-2026-43303 [HIGH] CWE-909 kernel: mm/page_alloc: clear page->private in free_pages_prepare()
kernel: mm/page_alloc: clear page->private in free_pages_prepare()
A flaw was found in the Linux kernel's memory management subsystem. When pages are freed, the page->private field is not properly cleared. If these pages are later reallocated as high-order pages and split, the tail pages can retain stale page->private values. This can lead to a use-after-free vulnerability in the swap subsystem, where incorrect assumptions about the page->private value can cause the system to crash.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Under investigation
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
No detection rules found.
No public exploits indexed.
Rapid7
Patch Tuesday - May 2026
blogs_rapid7·2026-05-13·CVSS 10.0
CVE-2026-41089 [CRITICAL] Patch Tuesday - May 2026
Microsoft is publishing 137 vulnerabilities on May 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild or public disclosure for any of these vulnerabilities. So far this month, Microsoft has provided patches to address 133 browser vulnerabilities, which are not included in the Patch Tuesday count above.
## Windows Netlogon: critical RCE
Anyone responsible for securing a domain controller should prioritize remediation of CVE-2026-41089 , which is a critical stack-based buffer overflow in Windows Netlogon with a CVSS v3 base score of 9.8. Exploitation leads to execution in the context of the Netlogon service, so that’s SYSTEM privileges on the domain controller. For most pentesters, that’s the point at which the customer report more or less writes itself. No privileges
Bugzilla
CVE-2026-43303 kernel: mm/page_alloc: clear page->private in free_pages_prepare()
bugzilla·2026-05-08
CVE-2026-43303 [HIGH] CVE-2026-43303 kernel: mm/page_alloc: clear page->private in free_pages_prepare()
CVE-2026-43303 kernel: mm/page_alloc: clear page->private in free_pages_prepare()
In the Linux kernel, the following vulnerability has been resolved:
mm/page_alloc: clear page->private in free_pages_prepare()
Several subsystems (slub, shmem, ttm, etc.) use page->private but don't
clear it before freeing pages. When these pages are later allocated as
high-order pages and split via split_page(), tail pages retain stale
page->private values.
This causes a use-after-free in the swap subsystem. The swap code uses
page->private to track swap count continuations, assuming freshly
allocated pages have page->private == 0. When stale values are present,
swap_count_continued() incorrectly assumes the continuation list is valid
and iterates over uninitialized page->lru containing LIST_POISON value
https://git.kernel.org/stable/c/23b82b7a26182ad840ae67d390d7ec9771e8c00fhttps://git.kernel.org/stable/c/3edb8ebbf79b9016040e8f3421d723ae3d542b32https://git.kernel.org/stable/c/ac1ea219590c09572ed5992dc233bbf7bb70fef9https://git.kernel.org/stable/c/d757c793853ec5483eb41ec2942c300b8fa720fbhttps://git.kernel.org/stable/c/e7790ab165713b79b1617ce659742ceb3a859d05https://git.kernel.org/stable/c/f9719e32a67b4b00b3c9b133e8b5ffa72a26b67b
2026-05-08
Published