PT-2025-22219 · Linux+9 · Linux Kernel+9

Published

2025-04-21

·

Updated

2026-05-26

·

CVE-2025-37958

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.14.0+
Description A vulnerability in the Linux kernel has been resolved, related to the migration of Transparent Huge Pages (THPs). When migrating a THP, concurrent access to the PMD migration entry during a deferred split scan can lead to an invalid address access. This issue can be prevented by checking the PMD migration entry and returning early. The vulnerability was found by syzkaller on an internal kernel and confirmed on upstream.
Recommendations For Linux kernel versions prior to 6.14.0+, update to version 6.14.0 or later to resolve the issue. As a temporary workaround, consider disabling the split huge pmd locked function until a patch is available. Restrict access to the mm/huge memory module to minimize the risk of exploitation. Avoid using the pmd to swp entry and pfn swap entry to page functions in the affected API endpoints until the issue is resolved.

Exploit

Fix

DoS

Buffer Overflow

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:11428
ALSA-2025:11861
AZL-62779
BDU:2025-14979
CVE-2025-37958
DLA-4327-1
DLA-4328-1
DSA-5973-1
ECHO-289A-B522-3012
INFSA-2025_11861
OESA-2025-1625
OESA-2025-1629
RHSA-2025:11428
RHSA-2025:11861
RHSA-2025:12209
RHSA-2025:12311
RHSA-2025:12525
RHSA-2025:12526
RHSA-2025:13135
RHSA-2025_11861
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:01972-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_01972-1
SUSE-SU-2025_02000-1
USN-7699-1
USN-7699-2
USN-7721-1
USN-7774-1
USN-7774-2
USN-7774-3
USN-7774-4
USN-7774-5
USN-7775-1
USN-7775-2
USN-7775-3
USN-7776-1
USN-7907-1
USN-7907-2
USN-7907-3
USN-7907-4
USN-7907-5
USN-7922-1
USN-7922-2
USN-7922-3
USN-7922-4
USN-7922-5
USN-7931-1
USN-7931-2
USN-7931-3
USN-7931-4
USN-7931-5
USN-7935-1
USN-7937-1
USN-7939-1
USN-7939-2
USN-7940-1
USN-7940-2

Affected Products

Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu