In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: avoid corrupting page->mapping in hugetlb_mcopy_atomic_pte
In MCOPY_ATOMIC_CONTINUE case with a non-shared VMA, pages in the page cache are installed in the ptes. But hugepage_add_new_anon_rmap is called for them mistakenly because they're not vm_shared. This will corrupt the page->mapping used by page cache code.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-x86_64Upgrade perf-debuginfoUpgrade kernel-livepatch-5.15.69-37.134Upgrade kernelUpgrade kernel-headersUpgrade bpftool-debuginfoUpgrade python-perf-debuginfoUpgrade python-perfUpgrade kernel-toolsUpgrade kernel-tools-develUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfo-common-aarch64Upgrade bpftoolUpgrade perfUpgrade kernel-develUpgrade kernel-debuginfo | Jul 9, 2025 | Jun 18, 2025 |
| Debian | — | Upgrade linux | Jun 20, 2025 | Jun 20, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 18, 2025 |
| Ubuntu | — | Upgrade linux-nvidiaUpgrade linux-azureUpgrade linux-gcpUpgrade linux-raspiUpgrade linux-intel-iotgUpgrade linux-lowlatencyUpgrade linux-oracle-5.15Upgrade linux-azure-5.15Upgrade linux-gkeUpgrade linux-gkeopUpgrade linux-gcp-5.15Upgrade linux-realtimeUpgrade linux-riscv-5.15Upgrade linux-oracleUpgrade linux-ibmUpgrade linux-intel-iotg-5.15Upgrade linux-kvmUpgrade linux-awsUpgrade linux-lowlatency-hwe-5.15Upgrade linux-hwe-5.15Upgrade linuxUpgrade linux-aws-5.15 | Jun 26, 2025 | Jun 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub