Executive brief
A vulnerability exists in the Linux kernel's memory management testing suite. When the system is configured to run specific virtual memory tests, it may fail to properly clean up internal memory tracking structures. This can lead to a situation where a new process accidentally accesses 'stale' memory information from a previous test, potentially causing system instability, crashes, or unauthorized data access.
Technical details
The vulnerability is caused by a failure to clear page table entries (PTEs) within the `destroy_args()` function of the `mm/debug_vm_pgtable` test suite. The test manually allocates an `mm_struct` and PTEs but does not invoke the standard `free_pgtables` path, leaving stale entries in the `mm_struct` slab. If a subsequent process is allocated the same `mm_struct` address, it may encounter these stale entries during its own page table operations, leading to incorrect RSS counter states and negative `pgtables_bytes` values. This is primarily reachable on kernels compiled with `CONFIG_DEBUG_VM_PGTABLE=y`. The fix involves explicitly clearing these entries using `*_clear` functions and utilizing `mmput()` to ensure the `mm_struct` is fully released.
Affected products
- Linux Linux Kernel CONFIG_DEBUG_VM_PGTABLE=y
Timeline
- 2025-09-11: advisory: CVE published by NVD
- 2025-08-28: patched: Fix committed to stable kernel trees
References
- https://git.kernel.org/stable/c/47d2a149611b8a94d24add9868c442a4af278658
- https://git.kernel.org/stable/c/561171db3b3eb759ba3f284dba7a76f4476ade03
- https://git.kernel.org/stable/c/61a9f2e5c49f05e3ea2c16674540a075a1b4be6f
- https://git.kernel.org/stable/c/63962ff932ef359925b94be2a88df6b4fd4fed0a
- https://git.kernel.org/stable/c/7bf57a0709cd7c9088cea8de023d6f4fbf2518b0
- https://git.kernel.org/stable/c/dde30854bddfb5d69f30022b53c5955a41088b33
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html