PT-2025-36319 · Linux+4 · Linux Kernel+4

Hch

·

Published

2025-06-27

·

Updated

2026-04-08

·

CVE-2025-39725

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue within the shrink folio list() function related to handling hardware-poisoned large folios. Specifically, the function fails to correctly handle large folios that have been marked as hardware-poisoned, potentially leading to a null pointer dereference and a kernel panic during memory reclamation. This occurs when memory reclamation for a large folio races with a memory failure, triggering a bug when unmap poisoned folio() attempts to handle the large folio. The issue arises from the inability of unmap poisoned folio() to handle large folios directly, and the failure to split the huge page table entry (PMD) before attempting unmapping. While unlikely in typical scenarios, the race condition can lead to system instability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15707
CVE-2025-39725
OESA-2025-2632
OESA-2025-2633
OESA-2025-2634
OESA-2025-2635
OESA-2025-2636
OESA-2025-2659
USN-7879-1
USN-7879-2
USN-7879-3
USN-7879-4
USN-7880-1
USN-7934-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu