CVE-2025-21815

HIGH

Linux Kernel 6.7-6.12.13, 6.13.0-6.13.2 - Out-of-bounds Read in Memory Compaction

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: mm/compaction: fix UBSAN shift-out-of-bounds warning syzkaller reported a UBSAN shift-out-of-bounds warning of (1UL << order) in isolate_freepages_block(). The bogus compound_order can be any value because it is union with flags. Add back the MAX_PAGE_ORDER check to fix the warning.

Scores

CVSS v3 7.1
EPSS 0.0018
EPSS Percentile 7.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-125
Status published
Products (11)
linux/Kernel 6.13.0 - 6.13.3linux
linux/Kernel 6.7.0 - 6.12.14linux
Linux/Linux < 6.7
Linux/Linux 3da0272a4c7d0d37b47b28e87014f421296fc2be - 10b7d3eb535098ccd4c82a182a33655d8a0e5c88
Linux/Linux 3da0272a4c7d0d37b47b28e87014f421296fc2be - 4491159774d973a9e2e998d25d8fbb20fada6dfa
Linux/Linux 3da0272a4c7d0d37b47b28e87014f421296fc2be - d1366e74342e75555af2648a2964deb2d5c92200
Linux/Linux 6.12.14 - 6.12.*
Linux/Linux 6.13.3 - 6.13.*
Linux/Linux 6.14
Linux/Linux 6.7
... and 1 more
Published Feb 27, 2025
Tracked Since Feb 18, 2026