{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-22090", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-12-29T08:45:45.817Z", "datePublished": "2025-04-16T14:12:42.561Z", "dateUpdated": "2026-08-05T11:56:44.221Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:56:44.221Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range()\n\nIf track_pfn_copy() fails, we already added the dst VMA to the maple\ntree. As fork() fails, we'll cleanup the maple tree, and stumble over\nthe dst VMA for which we neither performed any reservation nor copied\nany page tables.\n\nConsequently untrack_pfn() will see VM_PAT and try obtaining the\nPAT information from the page table -- which fails because the page\ntable was not copied.\n\nThe easiest fix would be to simply clear the VM_PAT flag of the dst VMA\nif track_pfn_copy() fails. However, the whole thing is about \"simply\"\nclearing the VM_PAT flag is shaky as well: if we passed track_pfn_copy()\nand performed a reservation, but copying the page tables fails, we'll\nsimply clear the VM_PAT flag, not properly undoing the reservation ...\nwhich is also wrong.\n\nSo let's fix it properly: set the VM_PAT flag only if the reservation\nsucceeded (leaving it clear initially), and undo the reservation if\nanything goes wrong while copying the page tables: clearing the VM_PAT\nflag after undoing the reservation.\n\nNote that any copied page table entries will get zapped when the VMA will\nget removed later, after copy_page_range() succeeded; as VM_PAT is not set\nthen, we won't try cleaning VM_PAT up once more and untrack_pfn() will be\nhappy. Note that leaving these page tables in place without a reservation\nis not a problem, as we are aborting fork(); this process will never run.\n\nA reproducer can trigger this usually at the first try:\n\n https://gitlab.com/davidhildenbrand/scratchspace/-/raw/main/reproducers/pat_fork.c\n\n WARNING: CPU: 26 PID: 11650 at arch/x86/mm/pat/memtype.c:983 get_pat_info+0xf6/0x110\n Modules linked in: ...\n CPU: 26 UID: 0 PID: 11650 Comm: repro3 Not tainted 6.12.0-rc5+ #92\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014\n RIP: 0010:get_pat_info+0xf6/0x110\n ...\n Call Trace:\n \n ...\n untrack_pfn+0x52/0x110\n unmap_single_vma+0xa6/0xe0\n unmap_vmas+0x105/0x1f0\n exit_mmap+0xf6/0x460\n __mmput+0x4b/0x120\n copy_process+0x1bf6/0x2aa0\n kernel_clone+0xab/0x440\n __do_sys_clone+0x66/0x90\n do_syscall_64+0x95/0x180\n\nLikely this case was missed in:\n\n d155df53f310 (\"x86/mm/pat: clear VM_PAT if copy_p4d_range failed\")\n\n... and instead of undoing the reservation we simply cleared the VM_PAT flag.\n\nKeep the documentation of these functions in include/linux/pgtable.h,\none place is more than sufficient -- we should clean that up for the other\nfunctions like track_pfn_remap/untrack_pfn separately." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H", "baseScore": 7.3, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The bug is triggered entirely through local syscalls — mmap() of a device node that creates a whole-VMA VM_PFNMAP/VM_PAT mapping followed by fork()/clone(). No network or remote peer data is involved.\nAC:L - Deterministic trigger paths exist with no race or attacker-uncontrollable state: track_pfn_copy() unconditionally returns -EINVAL for a COW VM_PAT mapping whose first page has been COWed, and get_pat_info() unconditionally WARNs for a shared VM_PAT mapping whose PTEs were zapped (vfio BAR reset, TTM eviction, fbdev VT switch); the maintainer notes a reproducer triggers \"usually at the first try\".\nPR:L - Only an unprivileged local user account is needed, provided it can mmap any device that uses whole-VMA remap_pfn_range()/vm_iomap_memory() — DRM render nodes, /dev/kfd, /dev/fb0, UIO and vfio-pci, all routinely granted to normal users, Android apps, or DPDK operator accounts. No capability check guards copy_page_range() or the PAT tracking path.\nUI:N - The attacking process performs the mmap, the write fault and the fork() itself; no action by any other user or victim process is required.\nS:U - The corruption is confined to kernel PAT bookkeeping and the attacking process's own address-space teardown; no VM, IOMMU or sandbox boundary is crossed.\nC:L - The WARN_ON_ONCE splat dumps kernel register state, RIP and a call trace (defeating KASLR for readers of the log), and destroying a live PAT reservation allows the same physical range to be re-mapped with an incompatible cache mode, exposing stale/incoherent data. There is no arbitrary kernel-memory read primitive.\nI:H - untrack_pfn() on the dst VMA frees a memtype reservation that still belongs to the live parent mapping, and the subsequent END_MATCH erase can silently truncate an unrelated memtype entry — destroying the kernel's only protection against conflicting cacheability aliases, which x86 defines as undefined behaviour causing CPU cache/data corruption.\nA:H - The bug produces a kernel WARNING/oops in get_pat_info() (an outright panic on the common panic_on_warn=1 hardening setting), and the sibling path permanently leaks a memtype reservation, blocking later remapping of that physical range and leaking kernel memory." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "arch/x86/mm/pat/memtype.c", "include/linux/pgtable.h", "kernel/fork.c", "mm/memory.c" ], "versions": [ { "version": "2ab640379a0ab4cef746ced1d7e04a0941774bcb", "lessThan": "a6623712ba8449876f0b3de9462831523fb851e4", "status": "affected", "versionType": "git" }, { "version": "2ab640379a0ab4cef746ced1d7e04a0941774bcb", "lessThan": "b07398e8a5da517083f5c3f2daa8f6681b48ab28", "status": "affected", "versionType": "git" }, { "version": "2ab640379a0ab4cef746ced1d7e04a0941774bcb", "lessThan": "8d6373f83f367dbed316ddeb178130a3a64b5b67", "status": "affected", "versionType": "git" }, { "version": "2ab640379a0ab4cef746ced1d7e04a0941774bcb", "lessThan": "da381c33f3aa6406406c9fdf07b8b0b63e0ce722", "status": "affected", "versionType": "git" }, { "version": "2ab640379a0ab4cef746ced1d7e04a0941774bcb", "lessThan": "de6185b8892d88142ef69768fe4077cbf40109c0", "status": "affected", "versionType": "git" }, { "version": "2ab640379a0ab4cef746ced1d7e04a0941774bcb", "lessThan": "dc84bc2aba85a1508f04a936f9f9a15f64ebfb31", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "arch/x86/mm/pat/memtype.c", "include/linux/pgtable.h", "kernel/fork.c", "mm/memory.c" ], "versions": [ { "version": "2.6.29", "status": "affected" }, { "version": "0", "lessThan": "2.6.29", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.160", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.87", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.23", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.13.11", "lessThanOrEqual": "6.13.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.14.2", "lessThanOrEqual": "6.14.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.15", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.29", "versionEndExcluding": "6.1.160" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.29", "versionEndExcluding": "6.6.87" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.29", "versionEndExcluding": "6.12.23" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.29", "versionEndExcluding": "6.13.11" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.29", "versionEndExcluding": "6.14.2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "2.6.29", "versionEndExcluding": "6.15" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/a6623712ba8449876f0b3de9462831523fb851e4" }, { "url": "https://git.kernel.org/stable/c/b07398e8a5da517083f5c3f2daa8f6681b48ab28" }, { "url": "https://git.kernel.org/stable/c/8d6373f83f367dbed316ddeb178130a3a64b5b67" }, { "url": "https://git.kernel.org/stable/c/da381c33f3aa6406406c9fdf07b8b0b63e0ce722" }, { "url": "https://git.kernel.org/stable/c/de6185b8892d88142ef69768fe4077cbf40109c0" }, { "url": "https://git.kernel.org/stable/c/dc84bc2aba85a1508f04a936f9f9a15f64ebfb31" } ], "title": "x86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range()", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "x_adpType": "supplier", "providerMetadata": { "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e", "shortName": "siemens-SADP", "dateUpdated": "2026-07-14T12:40:45.930Z" }, "affected": [ { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.6", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.6", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.6", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.6", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" }, { "vendor": "Siemens", "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP", "versions": [ { "status": "affected", "version": "V3.1.6", "lessThan": "*", "versionType": "custom" } ], "defaultStatus": "unknown" } ], "references": [ { "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html" } ] } ] } }