PT-2025-16730 · Linux+6 · Linux Kernel+6

Published

2025-03-25

·

Updated

2026-04-20

·

CVE-2025-22090

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.12.0-rc5+
Description A vulnerability in the Linux kernel has been resolved, related to the handling of VM PAT when fork() fails in copy page range(). If track pfn copy() fails, the dst VMA is added to the maple tree, but as fork() fails, the cleanup of the maple tree stumbles over the dst VMA for which no reservation or page table copy was performed. This leads to untrack pfn() trying to obtain PAT information from the page table, which fails because the page table was not copied. The issue is fixed by setting the VM PAT flag only if the reservation succeeds and undoing the reservation if anything goes wrong while copying the page tables.
Recommendations For Linux kernel versions prior to 6.12.0-rc5+, update to a newer version that includes the fix for the VM PAT handling issue. As a temporary workaround, consider disabling the fork() system call in scenarios where copy page range() may fail, until a patch is available. Restrict access to the copy page range() function to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Incorrect Privilege Assignment

Information Disclosure

Weakness Enumeration

Related Identifiers

AZL-69551
BDU:2026-01403
CVE-2025-22090
ECHO-9C94-41AB-8110
MGASA-2025-0142
MGASA-2025-0146
OESA-2026-1566
OESA-2026-1567
OESA-2026-1570
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01707-1
SUSE-SU-2025:01614-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:02969-1
SUSE-SU-2025:02996-1
SUSE-SU-2025:02997-1
SUSE-SU-2025:03011-1
SUSE-SU-2025:20343-1
SUSE-SU-2025:20344-1
SUSE-SU-2025:20354-1
SUSE-SU-2025:20355-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_02969-1
SUSE-SU-2025_02996-1
SUSE-SU-2025_02997-1
SUSE-SU-2025_03011-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1
USN-7835-1
USN-7835-2
USN-7835-3
USN-7835-4
USN-7835-5
USN-7835-6
USN-7887-1
USN-7887-2
USN-7940-1
USN-7940-2

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu