CVE-2025-40174

Source
https://cve.org/CVERecord?id=CVE-2025-40174
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40174.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-40174
Downstream
Published
2025-11-12T10:53:49Z
Modified
2026-08-12T03:51:09Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
x86/mm: Fix SMP ordering in switch_mm_irqs_off()
Details

In the Linux kernel, the following vulnerability has been resolved:

x86/mm: Fix SMP ordering in switch_mm_irqs_off()

Stephen noted that it is possible to not have an smp_mb() between the loaded_mm store and the tlb_gen load in switch_mm(), meaning the ordering against flush_tlb_mm_range() goes out the window, and it becomes possible for switch_mm() to not observe a recent tlb_gen update and fail to flush the TLBs.

[ dhansen: merge conflict fixed by Ingo ]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40174.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
209954cbc7d0ce1a190fc725d20ce303d74d2680
Fixed
0fe5e3f5fb75c5d88dad24dece3ee75e9d87adeb
Fixed
83b0177a6c4889b3a6e865da5e21b2c9d97d0551

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40174.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.17.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40174.json"