CVE-2026-68166: userfaultfd: prevent registration of special VMAs

Published Aug 10, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

userfaultfd: prevent registration of special VMAs

Vova Tokarev says:

userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can register on the shadow stack, discard a page ... and inject a page with chosen return addresses via UFFDIOCOPY.

Update vmacanuserfault() to reject VMSHADOWSTACK.

While on it, also reject VMSPECIAL so that if a driver would implement vmuffdops, it wouldn't be possible to register special VMAs with userfaultfd.

Since VMSPECIAL includes VMDONTEXPAND which is set but hugetlb, exclude hugetlb VMAs from the check for VMSPECIAL.

Affected Software

1 affected component
Linux Kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Update vma_can_userfault() to reject VM_SHADOW_STACK so userfaultfd registration is prevented for shadow stack VMAs.

    Linux kernel (vma_can_userfault / userfaultfd registration) VM_SHADOW_STACK acceptance = reject
  2. Configuration

    While on it, also reject VM_SPECIAL in vma_can_userfault() so special VMAs (including hugetlb VMAs that include VM_DONTEXPAND via VM_SPECIAL) are excluded from the userfaultfd registration check.

    Linux kernel (vma_can_userfault / userfaultfd registration) VM_SPECIAL acceptance = reject

Event History

Aug 10, 2026
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
Description
Data Sourced
via NVD·01:20 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-68166?

CVE-2026-68166 has a risk rating of 58.

2

How do I fix CVE-2026-68166?

To resolve CVE-2026-68166, ensure you update your Linux kernel to the latest version where the vulnerability has been patched.

3

What systems are affected by CVE-2026-68166?

CVE-2026-68166 affects systems running vulnerable versions of the Linux kernel that allow userfaultfd registration on special VMAs.

4

What impact does CVE-2026-68166 have on system security?

CVE-2026-68166 can potentially allow unauthorized page injection, undermining the integrity of the shadow stack.

5

Who can exploit CVE-2026-68166?

Any attacker with access to userfaultfd can exploit CVE-2026-68166 to manipulate vulnerable VMAs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203