In the Linux kernel, the following vulnerability has been resolved:
mm/filemap: fix filemap_get_folios_contig THP panic
Patch series "memfd-pin huge page fixes".
Fix multiple bugs that occur when using memfd_pin_folios with hugetlb pages and THP. The hugetlb bugs only bite when the page is not yet faulted in when memfd_pin_folios is called. The THP bug bites when the starting offset passed to memfd_pin_folios is not huge page aligned. See the commit messages for details.
This patch (of 5):
memfd_pin_folios on memory backed by THP panics if the requested start offset is not huge page aligned:
BUG: kernel NULL pointer dereference, address: 0000000000000036 RIP: 0010:filemap_get_folios_contig+0xdf/0x290 RSP: 0018:ffffc9002092fbe8 EFLAGS: 00010202 RAX: 0000000000000002 RBX: 0000000000000002 RCX: 0000000000000002
The fault occurs here, because xas_load returns a folio with value 2:
filemap_get_folios_contig() for (folio = xas_load(&xas); folio && xas.xa_index <= end; folio = xas_next(&xas)) { ... if (!folio_try_get(folio)) <-- BOOM
"2" is an xarray sibling entry. We get it because memfd_pin_folios does not round the indices passed to filemap_get_folios_contig to huge page boundaries for THP, so we load from the middle of a huge page range see a sibling. (It does round for hugetlbfs, at the is_file_hugepages test).
To fix, if the folio is a sibling, then return the next index as the starting point for the next call to filemap_get_folios_contig.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 21, 2024 |
| Ubuntu | — | Upgrade linux-image-oracleUpgrade linux-image-6.11.0-1009-awsUpgrade linux-image-awsUpgrade linux-image-realtimeUpgrade linux-image-6.11.0-1008-raspiUpgrade linux-image-oem-24.04bUpgrade linux-image-azure-fdeUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.11.0-1009-gcpUpgrade linux-image-6.11.0-1011-oracle-64kUpgrade linux-image-6.11.0-1010-lowlatency-64kUpgrade linux-image-oem-24.04Upgrade linux-image-generic-hwe-24.04Upgrade linux-image-raspiUpgrade linux-image-generic-64kUpgrade linux-image-6.11.0-18-genericUpgrade linux-image-azureUpgrade linux-image-6.11.0-1015-oemUpgrade linux-image-6.11.0-1009-azure-fdeUpgrade linux-image-lowlatency-64kUpgrade linux-image-genericUpgrade linux-image-6.11.0-1011-oracleUpgrade linux-image-oem-24.04aUpgrade linux-image-oracle-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.11.0-1005-realtimeUpgrade linux-image-6.11.0-1010-lowlatencyUpgrade linux-image-lowlatencyUpgrade linux-image-virtualUpgrade linux-image-6.11.0-18-generic-64kUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-6.11.0-1009-azureUpgrade linux-image-gcp | Feb 20, 2025 | Oct 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub