
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98226 is a Linux kernel vulnerability in the memory management (mm) swap subsystem, specifically a bit collision bug between SWAP_USAGE_OFFLIST_BIT and the real swap usage counter (si->inuse_pages). The flaw causes incorrect swap usage accounting on systems with large swap spaces (≥4 TiB with 4 KiB pages), potentially leading to data loss during swapoff and kernel state corruption. It affects Linux kernel version 6.14 (introduced at commit b228386cf237e659cdf5d8037a19db0b0a06f6b5) and is fixed in versions 6.18.54, 7.2.8, and 7.3-rc4. The vulnerability is estimated as Medium severity (Feedly).
SWAP_USAGE_OFFLIST_BIT is defined using BITS_PER_TYPE(atomic_t), placing it at bit 30 of the si->inuse_pages atomic counter. On systems with 4 KiB pages, this bit collides with the real usage count once swap usage reaches 2^30 pages (4 TiB). This is a case of incorrect bit-field design / integer overflow in flag embedding (CWE-190 or CWE-682). The collision manifests in two ways: (1) swap_usage_in_pages() masks bit 30, causing /proc/swaps to underreport usage by 4 TiB and causing try_to_unuse() to prematurely exit during swapoff when the masked count appears zero, tearing down the swap device while pages are still swapped out; (2) swap_usage_sub() misinterprets the set bit 30 as the OFFLIST flag, calls add_to_avail_list(), clears the bit (leaving the stored count 4 TiB low), and calls plist_add() on an already-listed device, triggering a WARN_ON(!plist_node_empty(node)) and double-linking the plist node (Feedly).
The primary impact is data loss: if swapoff is invoked when swap usage is exactly 2^30 pages, the kernel prematurely considers the swap device empty and tears it down while pages are still swapped out, permanently losing those pages and their data. Secondary impacts include kernel state corruption through a corrupted inuse_pages counter (understated by 4 TiB) and a doubly-linked plist node, which can cause unpredictable kernel behavior, potential system instability, or crashes. This vulnerability primarily affects high-memory servers or systems with very large swap configurations (≥4 TiB swap with 4 KiB pages) (Feedly).
There are no known public proof-of-concept exploits, no reported in-the-wild exploitation, and no threat actor attribution for CVE-2026-98226. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires a system with an extremely large swap space (≥4 TiB with 4 KiB pages), making it a niche condition limited to high-memory server environments. No EPSS score data is currently available (Feedly).
Apply the upstream kernel fixes included in Linux 6.18.54, 7.2.8, or 7.3-rc4. The specific fix commits are 0a41a46859df0d2bd7ed127197aac7c7389c00ed, 7c0d0d6de46076b43a2acaf1026b6648f8434c39, and 12e9ac7bc5b254048f886bf421e3a15491106c1f (Feedly). As a workaround for systems that cannot immediately upgrade, avoid using swap spaces of 4 TiB or larger (with 4 KiB pages), or avoid running swapoff when swap usage is near the 2^30 page threshold. Monitor /proc/swaps for anomalous usage values as a detection measure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."