CVE-2026-72412: s390/mm: Fix handling of _PAGE_UNUSED pte bit
In the Linux kernel, the following vulnerability has been resolved:
s390/mm: Fix handling of PAGEUNUSED pte bit
The PAGEUNUSED softbit should not really be lying around. Its sole purpose is to signal to trytounmapone() and trytomigrateone() that the page can be discarded instead of being moved / swapped.
KVM has no way to know why a page is being unmapped, so it sets the bit on userspace ptes corresponding to unused guest pages every time they get unmapped. KVM has no reasonable way to clear the bit once the page is in use again.
While setptes() checks and clears the bit, other paths that set new ptes did not. This led to used pages being thrown out as if they were unused, causing guest corruption.
Fix the issue by clearing the PAGEUNUSED bit for present ptes in setpte(), i.e. whenever a present pte is getting set. The check in setptes() is then redundant and can be removed.
Also fix gmaphelpertrysetpteunused() to only set the bit if the pte is present; the PAGEUNUSED bit is only defined for present ptes and thus should not be set for non-present ptes.