PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-52965 Linux CVE debrief

The Linux kernel was vulnerable to an infinite LRU walk on swapout failure in the drm/ttm module. This issue has been resolved by deferring del_bulk_move to the success path only. The vulnerability affected the Linux kernel's drm/ttm module, allowing for potential denial of service or privilege escalation. Linux kernel users and administrators should be aware of this vulnerability and take recommended actions to mitigate potential risks.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-24
Original CVE updated
2026-07-14
Advisory published
2026-06-24
Advisory updated
2026-07-14

Who should care

Linux kernel users, administrators, and security teams should be aware of this vulnerability and take recommended actions to mitigate potential risks. Affected operators and platforms may be exposed to potential denial of service or privilege escalation attacks.

Technical summary

The drm/ttm module in the Linux kernel was vulnerable to an infinite LRU walk on swapout failure. When ttm_tt_swapout() fails, the current code calls ttm_resource_add_bulk_move() followed by ttm_resource_move_to_lru_tail() to restore the resource's bulk_move membership. However, ttm_resource_move_to_lru_tail() places the resource at the tail of the LRU list, which puts the resource in front of the hitch node. The next list_for_each_entry_continue() from the hitch finds the same resource again, causing an infinite loop. The fix defers del_bulk_move to the success path only, preventing the infinite loop and potential denial of service or privilege escalation attacks.

Defensive priority

Medium

Recommended defensive actions

  • Apply the official patch or update the Linux kernel to the latest version
  • Review and monitor system logs for potential exploitation attempts
  • Implement compensating controls, such as restricting access to the affected system
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record was published on 2026-06-24T17:17:06.937Z and last modified on 2026-07-10T19:23:34.427Z. The NVD entry is currently Awaiting Analysis. Linux kernel users should verify their deployments and review official advisories for affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-52965 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-52965

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-52965 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52965

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0124a09e3e5f5f6080efe9663b27af27933f8382

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b2ed01e7ad3de80333e9b962a44024b094bc0b2b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.