Executive brief
A vulnerability in the Linux kernel's secret memory management could allow a local attacker to cause a system crash or potentially access sensitive data. The issue occurs when multiple programs try to access the same 'secret' memory area simultaneously, leading to a race condition that mishandles how memory is mapped. This could result in a denial of service (system crash) or unauthorized memory access, impacting the overall stability and security of the operating system.
Technical details
A race condition exists in the `mm/secretmem` fault handler when using `memfd_secret(2)`. When two tasks concurrently fault on the same secret memory page, both may allocate a folio and remove the page from the direct map. The task that fails to add its folio to the file mapping incorrectly frees the folio before restoring the page to the direct map. This creates a window where the page is available to the allocator but remains missing from the direct map, leading to a supervisor not-present page fault if another kernel task attempts to access it. The fix reorders the operations to ensure the direct map is restored before the folio is released.
Affected products
- Linux Linux Kernel 5.14 to 6.17.9
Timeline
- 2025-10-31: disclosed: Reported by Google Big Sleep
- 2025-12-06: advisory
- 2025-12-07: patched
References
- https://git.kernel.org/stable/c/1e4643d6628edf9c0047b1f8f5bc574665025acb
- https://git.kernel.org/stable/c/42d486d35a4143cc37fc72ee66edc99d942dd367
- https://git.kernel.org/stable/c/4444767e625da46009fc94a453fd1967b80ba047
- https://git.kernel.org/stable/c/52f2d5cf33de9a8f5e72bbb0ed38282ae0bc4649
- https://git.kernel.org/stable/c/6f86d0534fddfbd08687fa0f01479d4226bc3c3d
- https://git.kernel.org/stable/c/bb1c19636aedae39360e6fdbcaef4f2bcff25785