Executive brief
A synchronization issue in the Linux kernel's memory management system could allow a local attacker to cause system instability or potentially access restricted data. The flaw occurs when the system switches between different memory contexts on multi-core processors, failing to properly clear old memory address translations. This could lead to the processor using outdated information, resulting in unpredictable behavior or unauthorized memory access.
Technical details
A race condition exists in the x86/mm component of the Linux kernel due to improper SMP ordering in switch_mm_irqs_off(). The vulnerability stems from a missing memory barrier (smp_mb) between the loaded_mm store and the tlb_gen load. This lack of synchronization means switch_mm() may fail to observe a recent tlb_gen update from flush_tlb_mm_range() on another CPU. Consequently, the kernel may fail to flush the TLB when required, leading to stale TLB entries. An attacker with local access could potentially exploit this to bypass memory protections or cause a denial of service. The issue has been resolved by ensuring a memory barrier is present, either through an explicit smp_mb() or the atomic operation in cpumask_set_cpu().
Affected products
- Linux Linux Kernel 6.14 to 6.17.5
Timeline
- 2025-11-12: advisory: CVE published by kernel.org
- 2025-10-23: patched: Fix committed to stable tree