OESA-2025-1318

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1318
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-1318.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2025-1318
Upstream
Published
2025-03-21T11:08:25Z
Modified
2026-08-18T01:18:49Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
kernel security update
Details

The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86/mmu: Zap all roots when unmapping gfn range in TDP MMU

Zap both valid and invalid roots when zapping/unmapping a gfn range, as KVM must ensure it holds no references to the freed page after returning from the unmap operation. Most notably, the TDP MMU doesn't zap invalid roots in mmu_notifier callbacks. This leads to use-after-free and other issues if the mmu_notifier runs to completion while an invalid root zapper yields as KVM fails to honor the requirement that there must be no references to the page after the mmu_notifier returns.

The bug is most easily reproduced by hacking KVM to cause a collision between set_nx_huge_pages() and kvm_mmu_notifier_release(), but the bug exists between kvm_mmu_notifier_invalidate_range_start() and memslot updates as well. Invalidating a root ensures pages aren't accessible by the guest, and KVM won't read or write page data itself, but KVM will trigger e.g. kvm_set_pfn_dirty() when zapping SPTEs, and thus completing a zap of an invalid root after the mmu_notifier returns is fatal.

WARNING: CPU: 24 PID: 1496 at arch/x86/kvm/../../../virt/kvm/kvm_main.c:173 [kvm] RIP: 0010:kvm_is_zone_device_pfn+0x96/0xa0 [kvm] Call Trace: <TASK> kvm_set_pfn_dirty+0xa8/0xe0 [kvm] __handle_changed_spte+0x2ab/0x5e0 [kvm] __handle_changed_spte+0x2ab/0x5e0 [kvm] __handle_changed_spte+0x2ab/0x5e0 [kvm] zap_gfn_range+0x1f3/0x310 [kvm] kvm_tdp_mmu_zap_invalidated_roots+0x50/0x90 [kvm] kvm_mmu_zap_all_fast+0x177/0x1a0 [kvm] set_nx_huge_pages+0xb4/0x190 [kvm] param_attr_store+0x70/0x100 module_attr_store+0x19/0x30 kernfs_fop_write_iter+0x119/0x1b0 new_sync_write+0x11c/0x1b0 vfs_write+0x1cc/0x270 ksys_write+0x5f/0xe0 do_syscall_64+0x38/0xc0 entry_SYSCALL_64_after_hwframe+0x44/0xae </TASK>(CVE-2021-47639)

In the Linux kernel, the following vulnerability has been resolved:

ubifs: skip dumping tnc tree when zroot is null

Clearing slab cache will free all znode in memory and make c->zroot.znode = NULL, then dumping tnc tree will access c->zroot.znode which cause null pointer dereference.(CVE-2024-58058)

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5: Fix variable not being completed when function returns

When cmd_alloc_index(), fails cmd_work_handler() needs to complete ent->slotted before returning early. Otherwise the task which issued the command may hang:

mlx5_core 0000:01:00.0: cmd_work_handler:877:(pid 3880418): failed to allocate command entry INFO: task kworker/13:2:4055883 blocked for more than 120 seconds. Not tainted 4.19.90-25.44.v2101.ky10.aarch64 #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. kworker/13:2 D 0 4055883 2 0x00000228 Workqueue: events mlx5e_tx_dim_work [mlx5_core] Call trace: __switch_to+0xe8/0x150 __schedule+0x2a8/0x9b8 schedule+0x2c/0x88 schedule_timeout+0x204/0x478 wait_for_common+0x154/0x250 wait_for_completion+0x28/0x38 cmd_exec+0x7a0/0xa00 [mlx5_core] mlx5_cmd_exec+0x54/0x80 [mlx5_core] mlx5_core_modify_cq+0x6c/0x80 [mlx5_core] mlx5_core_modify_cq_moderation+0xa0/0xb8 [mlx5_core] mlx5e_tx_dim_work+0x54/0x68 [mlx5_core] process_one_work+0x1b0/0x448 worker_thread+0x54/0x468 kthread+0x134/0x138 ret_from_fork+0x10/0x18(CVE-2025-21662)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:22.03-LTS-SP3 / kernel

Package

Name
kernel
Purl
pkg:rpm/openEuler/kernel&distro=openEuler-22.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.10.0-254.0.0.157.oe2203sp3

Ecosystem specific

{
    "aarch64": [
        "kernel-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "kernel-debuginfo-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "kernel-debugsource-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "kernel-devel-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "kernel-headers-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "kernel-source-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "kernel-tools-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "kernel-tools-debuginfo-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "kernel-tools-devel-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "perf-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "perf-debuginfo-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "python3-perf-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm",
        "python3-perf-debuginfo-5.10.0-254.0.0.157.oe2203sp3.aarch64.rpm"
    ],
    "src": [
        "kernel-5.10.0-254.0.0.157.oe2203sp3.src.rpm"
    ],
    "x86_64": [
        "kernel-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "kernel-debuginfo-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "kernel-debugsource-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "kernel-devel-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "kernel-headers-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "kernel-source-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "kernel-tools-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "kernel-tools-debuginfo-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "kernel-tools-devel-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "perf-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "perf-debuginfo-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "python3-perf-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm",
        "python3-perf-debuginfo-5.10.0-254.0.0.157.oe2203sp3.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2025-1318.json"