Junglewise Threat Intelligence

CVE-2025-40270: Linux Kernel use-after-free in VMA readahead swap management

CVE-2025-40270 · Severity: high · CVSS 7.8 · Published 2025-12-06

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory management system could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system attempts to pre-load data from 'swap' storage (disk space used as extra memory) while that storage device is being disabled. This race condition can lead to a 'use-after-free' error, impacting system stability and security.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's mm/swap_state.c within the swap_vma_readahead function. The root cause is a failure to properly pin swap devices when the VMA readahead mechanism encounters swap entries belonging to a different device than the target entry. While the caller holds a reference to the primary swap device, it may access entries on a second device without a reference; if that second device is concurrently removed via swapoff, a UAF occurs during the call to __read_swap_cache_async. The fix introduces explicit swap device pinning via get_swap_device() when cross-device entries are encountered. This issue was introduced in kernel version 6.15 and is resolved in stable branches.

Affected products

  • Linux Linux 6.15 to 6.17.9

Timeline

  • 2025-11-11: other: Initial patch submitted
  • 2025-12-06: disclosed: CVE-2025-40270 published

References