Has this bug actually been observed at runtime, or is it a theoretical from-code-inspection thing?
We have a driver which changes vm_flags, and this bug is found by our testcases.
Thanks to everyone for your review and email instructions, I will do better next time.