In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: avoid corrupting page->mapping in hugetlb_mcopy_atomic_pte
In MCOPY_ATOMIC_CONTINUE case with a non-shared VMA, pages in the page cache are installed in the ptes. But hugepage_add_new_anon_rmap is called for them mistakenly because they're not vm_shared. This will corrupt the page->mapping used by page cache code.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-aarch64Upgrade kernel-debuginfoUpgrade kernel-tools-develUpgrade bpftoolUpgrade kernel-toolsUpgrade kernel-tools-debuginfoUpgrade perfUpgrade kernel-develUpgrade python-perf-debuginfoUpgrade kernel-headersUpgrade perf-debuginfoUpgrade python-perfUpgrade kernelUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-livepatch-5.15.69-37.134Upgrade bpftool-debuginfo | Jul 9, 2025 | Jun 18, 2025 |
| Debian | — | Upgrade linux | Jun 20, 2025 | Jun 20, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 18, 2025 |
| Ubuntu | — | Upgrade linux-oracleUpgrade linux-gkeopUpgrade linux-azure-5.15Upgrade linux-intel-iotgUpgrade linux-intel-iotg-5.15Upgrade linux-riscv-5.15Upgrade linux-gkeUpgrade linux-azureUpgrade linux-realtimeUpgrade linux-gcpUpgrade linux-oracle-5.15Upgrade linux-nvidiaUpgrade linux-raspiUpgrade linux-ibmUpgrade linux-gcp-5.15Upgrade linux-lowlatencyUpgrade linux-kvmUpgrade linux-hwe-5.15Upgrade linuxUpgrade linux-aws-5.15Upgrade linux-awsUpgrade linux-lowlatency-hwe-5.15 | Jun 26, 2025 | Jun 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub