Executive brief
A race condition in the Linux kernel's memory management tools could allow a local user to cause a system crash. The issue occurs when the system attempts to inspect memory structures while they are simultaneously being modified or removed during hardware changes. This primarily impacts system stability and availability in environments using specific hardware architectures or industrial controllers.
Technical details
A race condition exists in the Linux kernel's mm/ptdump component between memory hot-remove operations and page table dumping via debugfs. When intermediate levels of the kernel page table are freed during a hot-remove, the ptdump code (specifically ptdump_walk_pgd and ptdump_check_wx) may continue to dereference memory that has been freed or reallocated. This is a local attack vector requiring access to the debugfs interface (/sys/kernel/debug/kernel_page_tables). The fix involves moving the memory hotplug lock (get_online_mems) inside the generic ptdump_walk_pgd() function to ensure synchronization across all affected platforms including arm64, riscv, and s390.
Affected products
- Linux Linux Kernel arm64, riscv, s390 platforms
- Siemens SIMATIC CN 4100 < V5.0
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP >= V3.1.6
Timeline
- 2025-06-20: other: Initial patch authored
- 2025-09-04: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1636b5e9c3543b87d673e32a47e7c18698882425
- https://git.kernel.org/stable/c/3ee9a8c27bfd72c3f465004fa8455785d61be5e8
- https://git.kernel.org/stable/c/59305202c67fea50378dcad0cc199dbc13a0e99a
- https://git.kernel.org/stable/c/67995d4244694928ce701928e530b5b4adeb17b4
- https://git.kernel.org/stable/c/69bea84b06b5e779627e7afdbf4b60a7d231c76f
- https://git.kernel.org/stable/c/ac25ec5fa2bf6e606dc7954488e4dded272fa9cd
- https://git.kernel.org/stable/c/ca8c414499f2e5337a95a76be0d21b728ee31c6b