CVE-2025-38686

MEDIUM

Linux Kernel 6.8-6.12.42, 6.13.0-6.15.10, 6.16.0-6.16.1 - Denial of Service via UFFDIO_MOVE Migration PMD Entry

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: fix a crash in UFFDIO_MOVE when PMD is a migration entry When UFFDIO_MOVE encounters a migration PMD entry, it proceeds with obtaining a folio and accessing it even though the entry is swp_entry_t. Add the missing check and let split_huge_pmd() handle migration entries. While at it also remove unnecessary folio check. [[email protected]: remove extra folio check, per David]

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (15)
linux/Kernel 6.13.0 - 6.15.11linux
linux/Kernel 6.16.0 - 6.16.2linux
linux/Kernel 6.8.0 - 6.12.43linux
Linux/Linux < 6.8
Linux/Linux 6.12.43 - 6.12.*
Linux/Linux 6.15.11 - 6.15.*
Linux/Linux 6.16.2 - 6.16.*
Linux/Linux 6.17
Linux/Linux 6.8
Linux/Linux adef440691bab824e39c1b17382322d195e1fab0 - 1202abad7a7ccd28c426d2844771a387b07629a4
... and 5 more
Published Sep 04, 2025
Tracked Since Feb 18, 2026