Executive brief
A vulnerability in the Linux kernel's memory management system can cause systems to crash during boot or when accessing certain types of memory. This issue primarily affects high-performance servers using large amounts of persistent memory and specific memory paging configurations. An exploit or trigger of this flaw results in a kernel panic, leading to a complete system outage and loss of availability.
Technical details
A race condition or synchronization failure exists in the Linux kernel's memory management (mm) subsystem. When 'vmemmap_can_optimize' returns true, the optimized path in '__populate_section_memmap()' skips the synchronization of top-level Page Global Directory (PGD) entries. This occurs because 'vmemmap_populate_compound_pages()' is implemented in core MM code which historically relied on architecture-specific code to manually handle synchronization. On x86 systems with 4-level paging and large persistent memory, this results in new PGD entries being installed only in 'init_mm.pgd' and not in other active tasks. When a task attempts to access the vmemmap region before synchronization, it triggers a supervisor write access page fault and a subsequent kernel panic. The fix introduces '{pgd,p4d}_populate_kernel()' to ensure explicit synchronization during entry installation.
Affected products
- Linux Linux Kernel 6.7 to 6.12.46, 6.13 to 6.16.6, 6.17-rc1 to 6.17-rc4
Timeline
- 2025-08-18: other: Initial patch submitted by Harry Yoo (Oracle)
- 2025-09-09: patched: Patches committed to stable kernel branches
- 2025-09-19: advisory: CVE-2025-39844 published
References
- https://git.kernel.org/stable/c/469f9d22751472b81eaaf8a27fcdb5a70741c342
- https://git.kernel.org/stable/c/4f7537772011fad832f83d6848f8eab282545bef
- https://git.kernel.org/stable/c/6797a8b3f71b2cb558b8771a03450dc3e004e453
- https://git.kernel.org/stable/c/732e62212f49d549c91071b4da7942ee3058f7a2
- https://git.kernel.org/stable/c/7cc183f2e67d19b03ee5c13a6664b8c6cc37ff9d
- https://git.kernel.org/stable/c/eceb44e1f94bd641b2a4e8c09b64c797c4eabc15
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html