In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: avoid corrupting page->mapping in hugetlb_mcopy_atomic_pte
In MCOPY_ATOMIC_CONTINUE case with a non-shared VMA, pages in the page cache are installed in the ptes. But hugepage_add_new_anon_rmap is called for them mistakenly because they're not vm_shared. This will corrupt the page->mapping used by page cache code.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade bpftool-debuginfoUpgrade perf-debuginfoUpgrade python-perfUpgrade kernel-livepatch-5.15.69-37.134Upgrade kernel-debuginfo-common-x86_64Upgrade python-perf-debuginfoUpgrade kernel-headersUpgrade kernelUpgrade perfUpgrade kernel-debuginfo-common-aarch64Upgrade bpftoolUpgrade kernel-develUpgrade kernel-tools-debuginfoUpgrade kernel-tools-develUpgrade kernel-debuginfoUpgrade kernel-tools | Jul 9, 2025 | Jun 18, 2025 |
| Debian | — | Upgrade linux | Jun 20, 2025 | Jun 20, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 18, 2025 |
| Ubuntu | — | Upgrade linux-kvmUpgrade linux-gkeUpgrade linux-oracle-5.15Upgrade linux-intel-iotgUpgrade linux-azure-5.15Upgrade linux-ibmUpgrade linux-riscv-5.15Upgrade linux-nvidiaUpgrade linux-azureUpgrade linux-aws-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linuxUpgrade linux-awsUpgrade linux-hwe-5.15Upgrade linux-gcp-5.15Upgrade linux-lowlatencyUpgrade linux-gcpUpgrade linux-raspiUpgrade linux-intel-iotg-5.15Upgrade linux-realtimeUpgrade linux-oracleUpgrade linux-gkeop | Jun 26, 2025 | Jun 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub