Wind River Support Network

HomeDefectsLIN1023-13702
Acknowledged

LIN1023-13702 : Security Advisory - linux - CVE-2025-38085

Created: Jun 29, 2025    Updated: Jul 8, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race  huge_pmd_unshare() drops a reference on a page table that may have previously been shared across processes, potentially turning it into a normal page table used in another process in which unrelated VMAs can afterwards be installed.  If this happens in the middle of a concurrent gup_fast(), gup_fast() could end up walking the page tables of another process.  While I don't see any way in which that immediately leads to kernel memory corruption, it is really weird and unexpected.  Fix it with an explicit broadcast IPI through tlb_remove_table_sync_one(), just like we do in khugepaged when removing page tables for a THP collapse.

CREATE(Triage):(User=lchen-cn) CVE-2025-38085 (https://nvd.nist.gov/vuln/detail/CVE-2025-38085)
Live chat
Online