{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-22034", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-12-29T08:45:45.808Z", "datePublished": "2025-04-16T14:11:53.301Z", "dateUpdated": "2026-08-05T11:56:06.819Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:56:06.819Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/gup: reject FOLL_SPLIT_PMD with hugetlb VMAs\n\nPatch series \"mm: fixes for device-exclusive entries (hmm)\", v2.\n\nDiscussing the PageTail() call in make_device_exclusive_range() with\nWilly, I recently discovered [1] that device-exclusive handling does not\nproperly work with THP, making the hmm-tests selftests fail if THPs are\nenabled on the system.\n\nLooking into more details, I found that hugetlb is not properly fenced,\nand I realized that something that was bugging me for longer -- how\ndevice-exclusive entries interact with mapcounts -- completely breaks\nmigration/swapout/split/hwpoison handling of these folios while they have\ndevice-exclusive PTEs.\n\nThe program below can be used to allocate 1 GiB worth of pages and making\nthem device-exclusive on a kernel with CONFIG_TEST_HMM.\n\nOnce they are device-exclusive, these folios cannot get swapped out\n(proc$pid/smaps_rollup will always indicate 1 GiB RSS no matter how much\none forces memory reclaim), and when having a memory block onlined to\nZONE_MOVABLE, trying to offline it will loop forever and complain about\nfailed migration of a page that should be movable.\n\n# echo offline > /sys/devices/system/memory/memory136/state\n# echo online_movable > /sys/devices/system/memory/memory136/state\n# ./hmm-swap &\n... wait until everything is device-exclusive\n# echo offline > /sys/devices/system/memory/memory136/state\n[ 285.193431][T14882] page: refcount:2 mapcount:0 mapping:0000000000000000\n index:0x7f20671f7 pfn:0x442b6a\n[ 285.196618][T14882] memcg:ffff888179298000\n[ 285.198085][T14882] anon flags: 0x5fff0000002091c(referenced|uptodate|\n dirty|active|owner_2|swapbacked|node=1|zone=3|lastcpupid=0x7ff)\n[ 285.201734][T14882] raw: ...\n[ 285.204464][T14882] raw: ...\n[ 285.207196][T14882] page dumped because: migration failure\n[ 285.209072][T14882] page_owner tracks the page as allocated\n[ 285.210915][T14882] page last allocated via order 0, migratetype\n Movable, gfp_mask 0x140dca(GFP_HIGHUSER_MOVABLE|__GFP_COMP|__GFP_ZERO),\n id 14926, tgid 14926 (hmm-swap), ts 254506295376, free_ts 227402023774\n[ 285.216765][T14882] post_alloc_hook+0x197/0x1b0\n[ 285.218874][T14882] get_page_from_freelist+0x76e/0x3280\n[ 285.220864][T14882] __alloc_frozen_pages_noprof+0x38e/0x2740\n[ 285.223302][T14882] alloc_pages_mpol+0x1fc/0x540\n[ 285.225130][T14882] folio_alloc_mpol_noprof+0x36/0x340\n[ 285.227222][T14882] vma_alloc_folio_noprof+0xee/0x1a0\n[ 285.229074][T14882] __handle_mm_fault+0x2b38/0x56a0\n[ 285.230822][T14882] handle_mm_fault+0x368/0x9f0\n...\n\nThis series fixes all issues I found so far. There is no easy way to fix\nwithout a bigger rework/cleanup. I have a bunch of cleanups on top (some\nprevious sent, some the result of the discussion in v1) that I will send\nout separately once this landed and I get to it.\n\nI wish we could just use some special present PROT_NONE PTEs instead of\nthese (non-present, non-none) fake-swap entries; but that just results in\nthe same problem we keep having (lack of spare PTE bits), and staring at\nother similar fake-swap entries, that ship has sailed.\n\nWith this series, make_device_exclusive() doesn't actually belong into\nmm/rmap.c anymore, but I'll leave moving that for another day.\n\nI only tested this series with the hmm-tests selftests due to lack of HW,\nso I'd appreciate some testing, especially if the interaction between two\nGPUs wanting a device-exclusive entry works as expected.\n\n\n#include \n#include \n#include \n#include \n#include \n#include \n#include \n#include \n#include \n#include \n\n#define HMM_DMIRROR_EXCLUSIVE _IOWR('H', 0x05, struct hmm_dmirror_cmd)\n\nstruct hmm_dmirror_cmd {\n\t__u64 addr;\n\t__u64 ptr;\n\t__u64 npages;\n\t__u64 cpages;\n\t__u64 faults;\n};\n\nconst size_t size = 1 * 1024 * 1024 * 1024ul;\nconst size_t chunk_size = 2 * 1024 * 1024ul;\n\nint m\n---truncated---" } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - Triggering requires local access — mmap of a hugetlb region plus DRM render-node ioctls to set up nouveau SVM and issue a GPU atomic fault (or the `/dev/hmm_dmirror` ioctl on CONFIG_TEST_HMM kernels). There is no network-reachable path to `make_device_exclusive_range()`.\nAC:L - No race or memory-layout luck is involved; the attacker deterministically creates the hugetlb VMA and directs a GPU atomic access at it, and `pmd_trans_huge()` is unconditionally true for a PMD-sized hugetlb entry. Nouveau SVM is enabled in mainstream distro kernels and hugepage pools are standard on GPU/HPC/database hosts, so nothing required is outside the attacker's control.\nPR:L - `NOUVEAU_SVM_INIT`/`NOUVEAU_SVM_BIND` are `DRM_RENDER_ALLOW`, reachable by any user who can open `/dev/dri/renderD*` (world- or render-group accessible on desktops and GPU compute nodes), and `mmap(MAP_ANONYMOUS|MAP_HUGETLB)` requires no capability. A plain unprivileged local account suffices.\nUI:N - The attacking process performs every step itself — allocating the hugetlb mapping, binding SVM, and issuing the GPU atomic operation. No victim action or cooperation is needed.\nS:U - The page-table and hugetlb-folio corruption occurs within the kernel that already manages the attacking process, yielding standard local privilege escalation. No VM, IOMMU, or other security-authority boundary is crossed.\nC:H - After the PMD is replaced with a normal PTE table, `hugetlb_wp()` calls `copy_user_large_folio()` with the page-table page as the source, copying raw PTE contents — physical addresses defeating KASLR/physmap randomization — into an attacker-readable hugepage. The subsequent use-after-free on the freed page table gives a broad kernel read primitive.\nI:H - `folio_put()`/`hugetlb_remove_rmap()` are applied to a page-table page that is still installed in the process's page tables, so it is freed and reallocated while live, giving stale PTEs that translate to arbitrary physical memory — a direct arbitrary-write primitive. Hugetlb folio refcount underflow and corrupted RSS/mapcount accounting compound this.\nA:H - The commit's own trace shows an immediate `kernel BUG at mm/page_table_check.c:87` (`Oops: invalid opcode`) from `pmdp_huge_clear_flush()` under CONFIG_PAGE_TABLE_CHECK. Without that debug option the resulting page-table corruption and refcount underflow reliably panic the kernel, and the trigger is repeatable at will." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "mm/gup.c" ], "versions": [ { "version": "9cb28da54643ad464c47585cd5866c30b0218e67", "lessThan": "2e877ff3492267def06dd50cb165dc9ab8838e7d", "status": "affected", "versionType": "git" }, { "version": "9cb28da54643ad464c47585cd5866c30b0218e67", "lessThan": "48d28417c66cce2f3b0ba773fcb6695a56eff220", "status": "affected", "versionType": "git" }, { "version": "9cb28da54643ad464c47585cd5866c30b0218e67", "lessThan": "fd900832e8440046627b60697687ab5d04398008", "status": "affected", "versionType": "git" }, { "version": "9cb28da54643ad464c47585cd5866c30b0218e67", "lessThan": "8977752c8056a6a094a279004a49722da15bace3", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "mm/gup.c" ], "versions": [ { "version": "6.10", "status": "affected" }, { "version": "0", "lessThan": "6.10", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.23", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.13.11", "lessThanOrEqual": "6.13.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.14.2", "lessThanOrEqual": "6.14.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.15", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.10", "versionEndExcluding": "6.12.23" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.10", "versionEndExcluding": "6.13.11" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.10", "versionEndExcluding": "6.14.2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.10", "versionEndExcluding": "6.15" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/2e877ff3492267def06dd50cb165dc9ab8838e7d" }, { "url": "https://git.kernel.org/stable/c/48d28417c66cce2f3b0ba773fcb6695a56eff220" }, { "url": "https://git.kernel.org/stable/c/fd900832e8440046627b60697687ab5d04398008" }, { "url": "https://git.kernel.org/stable/c/8977752c8056a6a094a279004a49722da15bace3" } ], "title": "mm/gup: reject FOLL_SPLIT_PMD with hugetlb VMAs", "x_generator": { "engine": "bippy-1.2.0" } } } }