In the Linux kernel, the following vulnerability has been resolved:
mm: use aligned address in clear_gigantic_page()
In current kernel, hugetlb_no_page() calls folio_zero_user() with the fault address. Where the fault address may be not aligned with the huge page size. Then, folio_zero_user() may call clear_gigantic_page() with the address, while clear_gigantic_page() requires the address to be huge page size aligned. So, this may cause memory corruption or information leak, addtional, use more obvious naming 'addr_hint' instead of 'addr' for clear_gigantic_page().
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 11, 2025 |
| Ubuntu | — | Upgrade linux-image-6.11.0-1013-oracle-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-virtualUpgrade linux-image-oem-24.04aUpgrade linux-image-6.11.0-1012-azureUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-6.11.0-1013-oracleUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-lowlatencyUpgrade linux-image-gcpUpgrade linux-image-6.11.0-21-generic-64kUpgrade linux-image-azure-fdeUpgrade linux-image-azureUpgrade linux-image-6.11.0-1011-lowlatency-64kUpgrade linux-image-6.11.0-1012-azure-fdeUpgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-oem-24.04bUpgrade linux-image-oracle-64kUpgrade linux-image-6.11.0-1011-gcp-64kUpgrade linux-image-6.11.0-1007-realtimeUpgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-awsUpgrade linux-image-6.11.0-1017-oemUpgrade linux-image-oem-24.04Upgrade linux-image-6.11.0-1011-awsUpgrade linux-image-oracleUpgrade linux-image-raspiUpgrade linux-image-6.11.0-1010-raspiUpgrade linux-image-genericUpgrade linux-image-6.11.0-1011-lowlatencyUpgrade linux-image-gcp-64kUpgrade linux-image-realtimeUpgrade linux-image-6.11.0-21-genericUpgrade linux-image-generic-64kUpgrade linux-image-lowlatency-64kUpgrade linux-image-6.11.0-1011-gcp | Mar 28, 2025 | Jan 11, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub