Junglewise Threat Intelligence

CVE-2025-40006: Linux Kernel race condition in HugeTLB folio deletion

CVE-2025-40006 · Severity: high · CVSS 7.8 · Published 2025-10-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory management system could allow a local user to cause a system crash. The issue occurs when the system attempts to delete large memory pages (HugeTLB) while they are simultaneously being moved or accessed. This race condition leads to internal kernel errors, potentially disrupting operations or allowing for further system instability.

Technical details

A race condition exists in the Linux kernel's mm/hugetlb component between folio migration and hole punching (fallocate). The function remove_inode_single_folio checks if a folio is mapped without holding the folio lock. If migration occurs simultaneously, folio_mapped() may incorrectly return false because the PTE has been converted to a migration entry. This results in the folio being deleted while still mapped, triggering a BUG in filemap_unaccount_folio. The fix involves acquiring the folio lock before checking the mapping status to synchronize with concurrent migration processes.

Affected products

  • Linux Linux Kernel 4.5 to 6.11.y

Timeline

  • 2025-09-12: disclosed: Initial patch submission
  • 2025-10-20: advisory: CVE-2025-40006 published

References

Related threats