CVE-2025-38085

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-38085
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38085.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-38085
Downstream
Related
Published
2025-06-28T08:15:24Z
Modified
2025-08-12T21:01:19Z
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

mm/hugetlb: fix hugepmdunshare() vs GUP-fast race

hugepmdunshare() drops a reference on a page table that may have previously been shared across processes, potentially turning it into a normal page table used in another process in which unrelated VMAs can afterwards be installed.

If this happens in the middle of a concurrent gupfast(), gupfast() could end up walking the page tables of another process. While I don't see any way in which that immediately leads to kernel memory corruption, it is really weird and unexpected.

Fix it with an explicit broadcast IPI through tlbremovetablesyncone(), just like we do in khugepaged when removing page tables for a THP collapse.

References

Affected packages