CVE-2025-39725
In the Linux kernel, the following vulnerability has been resolved:
mm/vmscan: fix hwpoisoned large folio handling in shrink_folio_list
In shrink_folio_list(), the hwpoisoned folio may be large folio, which can't be handled by unmap_poisoned_folio(). For THP, try_to_unmap_one() must be passed with TTU_SPLIT_HUGE_PMD to split huge PMD first and then retry. Without TTU_SPLIT_HUGE_PMD, we will trigger null-ptr deref of pvmw.pte. Even we passed TTU_SPLIT_HUGE_PMD, we will trigger a WARN_ON_ONCE due to the page isn't in swapcache.
Since UCE is rare in real world, and race with reclaimation is more rare, just skipping the hwpoisoned large folio is enough. memory_failure() will handle it if the UCE is triggered again.
Leer descripción completaMostrar menos
This happens when memory reclaim for large folio races with memory_failure(), and will lead to kernel panic. The race is as follows:
[tujinjiang@huawei.com: add comment to unmap_poisoned_folio()]
Detalles técnicos trazas, registros y código del informe original
cpu0 cpu1 shrink_folio_list memory_failure TestSetPageHWPoison unmap_poisoned_folio --> trigger BUG_ON due to unmap_poisoned_folio couldn't handle large folio
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.15%
- Percentil entre todas las CVEs puntuadas: 3
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-476
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-39725",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "1c9798bf8145a92abf45aa9d38a6406d9eb8bdf0",
"lessThan": "656eaddbc952e1baae2f69281c22debe22140312",
"versionType": "git"
},
{
"status": "affected",
"version": "1b0449544c6482179ac84530b61fc192a6527bfd",
"lessThan": "c1101113d45838a823188ae25c61af97552a28ae",
"versionType": "git"
},
{
"status": "affected",
"version": "1b0449544c6482179ac84530b61fc192a6527bfd",
"lessThan": "9f1e8cd0b7c4c944e9921b52a6661b5eda2705ab",
"versionType": "git"
},
{
"status": "affected",
"version": "912e9f0300c3564b72a8808db406e313193a37ad",
"versionType": "git"
},
{
"status": "affected",
"version": "6.12.26",
"lessThan": "6.12.41",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.14.5",
"lessThan": "6.15",
"versionType": "semver"
}
],
"programFiles": [
"mm/memory-failure.c",
"mm/vmscan.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.41",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.15.9",
"versionType": "semver",
"lessThanOrEqual": "6.15.*"
},
{
"status": "unaffected",
"version": "6.16",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"mm/memory-failure.c",
"mm/vmscan.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-09-05T18:15:50.320",
"references": [
{
"url": "https://git.kernel.org/stable/c/656eaddbc952e1baae2f69281c22debe22140312",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9f1e8cd0b7c4c944e9921b52a6661b5eda2705ab",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c1101113d45838a823188ae25c61af97552a28ae",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-476"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmscan: fix hwpoisoned large folio handling in shrink_folio_list\n\nIn shrink_folio_list(), the hwpoisoned folio may be large folio, which\ncan't be handled by unmap_poisoned_folio(). For THP, try_to_unmap_one()\nmust be passed with TTU_SPLIT_HUGE_PMD to split huge PMD first and then\nretry. Without TTU_SPLIT_HUGE_PMD, we will trigger null-ptr deref of\npvmw.pte. Even we passed TTU_SPLIT_HUGE_PMD, we will trigger a\nWARN_ON_ONCE due to the page isn't in swapcache.\n\nSince UCE is rare in real world, and race with reclaimation is more rare,\njust skipping the hwpoisoned large folio is enough. memory_failure() will\nhandle it if the UCE is triggered again.\n\nThis happens when memory reclaim for large folio races with\nmemory_failure(), and will lead to kernel panic. The race is as\nfollows:\n\ncpu0 cpu1\n shrink_folio_list memory_failure\n TestSetPageHWPoison\n unmap_poisoned_folio\n --> trigger BUG_ON due to\n unmap_poisoned_folio couldn't\n handle large folio\n\n[tujinjiang@huawei.com: add comment to unmap_poisoned_folio()]"
}
],
"lastModified": "2026-06-17T09:18:21.300",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "19B129C6-1ABE-4712-8AB0-009FB92F8F2B",
"versionEndExcluding": "6.12.41",
"versionStartIncluding": "6.12.26"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E63E673B-291A-456D-A515-12B29693073E",
"versionEndExcluding": "6.15.9",
"versionStartIncluding": "6.14.5"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6D4894DB-CCFE-4602-B1BF-3960B2E19A01"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "09709862-E348-4378-8632-5A7813EDDC86"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "415BF58A-8197-43F5-B3D7-D1D63057A26E"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A0517869-312D-4429-80C2-561086E1421C"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85421F4E-C863-4ABF-B4B4-E887CC2F7F92"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3827F0D4-5FEE-4181-B267-5A45E7CA11FC"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A9C2DE5-43B8-4D73-BDB5-EA55C7671A52"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}