CVE-2025-39899

MEDIUM

Linux Kernel - Denial of Service via kmap_local LIFO Ordering Violation in userfaultfd

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: mm/userfaultfd: fix kmap_local LIFO ordering for CONFIG_HIGHPTE With CONFIG_HIGHPTE on 32-bit ARM, move_pages_pte() maps PTE pages using kmap_local_page(), which requires unmapping in Last-In-First-Out order. The current code maps dst_pte first, then src_pte, but unmaps them in the same order (dst_pte, src_pte), violating the LIFO requirement. This causes the warning in kunmap_local_indexed(): WARNING: CPU: 0 PID: 604 at mm/highmem.c:622 kunmap_local_indexed+0x178/0x17c addr \!= __fix_to_virt(FIX_KMAP_BEGIN + idx) Fix this by reversing the unmap order to respect LIFO ordering. This issue follows the same pattern as similar fixes: - commit eca6828403b8 ("crypto: skcipher - fix mismatch between mapping and unmapping order") - commit 8cf57c6df818 ("nilfs2: eliminate staggered calls to kunmap in nilfs_rename") Both of which addressed the same fundamental requirement that kmap_local operations must follow LIFO ordering.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (12)
linux/Kernel 6.13.0 - 6.16.6linux
linux/Kernel 6.8.0 - 6.12.46linux
Linux/Linux < 6.8
Linux/Linux 6.12.46 - 6.12.*
Linux/Linux 6.16.6 - 6.16.*
Linux/Linux 6.17
Linux/Linux 6.8
Linux/Linux adef440691bab824e39c1b17382322d195e1fab0 - 9614d8bee66387501f48718fa306e17f2aa3f2f3
Linux/Linux adef440691bab824e39c1b17382322d195e1fab0 - b051f707018967ea8f697d790a1ed8c443f63812
Linux/Linux adef440691bab824e39c1b17382322d195e1fab0 - bd1ee62759d0bd4d6b909731c076c230ac89d61e
... and 2 more
Published Oct 01, 2025
Tracked Since Feb 18, 2026