{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-22034",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-12-29T08:45:45.808Z",
        "datePublished": "2025-04-16T14:11:53.301Z",
        "dateUpdated": "2026-08-05T11:56:06.819Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:56:06.819Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/gup: reject FOLL_SPLIT_PMD with hugetlb VMAs\n\nPatch series \"mm: fixes for device-exclusive entries (hmm)\", v2.\n\nDiscussing the PageTail() call in make_device_exclusive_range() with\nWilly, I recently discovered [1] that device-exclusive handling does not\nproperly work with THP, making the hmm-tests selftests fail if THPs are\nenabled on the system.\n\nLooking into more details, I found that hugetlb is not properly fenced,\nand I realized that something that was bugging me for longer -- how\ndevice-exclusive entries interact with mapcounts -- completely breaks\nmigration/swapout/split/hwpoison handling of these folios while they have\ndevice-exclusive PTEs.\n\nThe program below can be used to allocate 1 GiB worth of pages and making\nthem device-exclusive on a kernel with CONFIG_TEST_HMM.\n\nOnce they are device-exclusive, these folios cannot get swapped out\n(proc$pid/smaps_rollup will always indicate 1 GiB RSS no matter how much\none forces memory reclaim), and when having a memory block onlined to\nZONE_MOVABLE, trying to offline it will loop forever and complain about\nfailed migration of a page that should be movable.\n\n# echo offline > /sys/devices/system/memory/memory136/state\n# echo online_movable > /sys/devices/system/memory/memory136/state\n# ./hmm-swap &\n... wait until everything is device-exclusive\n# echo offline > /sys/devices/system/memory/memory136/state\n[  285.193431][T14882] page: refcount:2 mapcount:0 mapping:0000000000000000\n  index:0x7f20671f7 pfn:0x442b6a\n[  285.196618][T14882] memcg:ffff888179298000\n[  285.198085][T14882] anon flags: 0x5fff0000002091c(referenced|uptodate|\n  dirty|active|owner_2|swapbacked|node=1|zone=3|lastcpupid=0x7ff)\n[  285.201734][T14882] raw: ...\n[  285.204464][T14882] raw: ...\n[  285.207196][T14882] page dumped because: migration failure\n[  285.209072][T14882] page_owner tracks the page as allocated\n[  285.210915][T14882] page last allocated via order 0, migratetype\n  Movable, gfp_mask 0x140dca(GFP_HIGHUSER_MOVABLE|__GFP_COMP|__GFP_ZERO),\n  id 14926, tgid 14926 (hmm-swap), ts 254506295376, free_ts 227402023774\n[  285.216765][T14882]  post_alloc_hook+0x197/0x1b0\n[  285.218874][T14882]  get_page_from_freelist+0x76e/0x3280\n[  285.220864][T14882]  __alloc_frozen_pages_noprof+0x38e/0x2740\n[  285.223302][T14882]  alloc_pages_mpol+0x1fc/0x540\n[  285.225130][T14882]  folio_alloc_mpol_noprof+0x36/0x340\n[  285.227222][T14882]  vma_alloc_folio_noprof+0xee/0x1a0\n[  285.229074][T14882]  __handle_mm_fault+0x2b38/0x56a0\n[  285.230822][T14882]  handle_mm_fault+0x368/0x9f0\n...\n\nThis series fixes all issues I found so far.  There is no easy way to fix\nwithout a bigger rework/cleanup.  I have a bunch of cleanups on top (some\nprevious sent, some the result of the discussion in v1) that I will send\nout separately once this landed and I get to it.\n\nI wish we could just use some special present PROT_NONE PTEs instead of\nthese (non-present, non-none) fake-swap entries; but that just results in\nthe same problem we keep having (lack of spare PTE bits), and staring at\nother similar fake-swap entries, that ship has sailed.\n\nWith this series, make_device_exclusive() doesn't actually belong into\nmm/rmap.c anymore, but I'll leave moving that for another day.\n\nI only tested this series with the hmm-tests selftests due to lack of HW,\nso I'd appreciate some testing, especially if the interaction between two\nGPUs wanting a device-exclusive entry works as expected.\n\n<program>\n#include <stdio.h>\n#include <fcntl.h>\n#include <stdint.h>\n#include <unistd.h>\n#include <stdlib.h>\n#include <string.h>\n#include <sys/mman.h>\n#include <sys/ioctl.h>\n#include <linux/types.h>\n#include <linux/ioctl.h>\n\n#define HMM_DMIRROR_EXCLUSIVE _IOWR('H', 0x05, struct hmm_dmirror_cmd)\n\nstruct hmm_dmirror_cmd {\n\t__u64 addr;\n\t__u64 ptr;\n\t__u64 npages;\n\t__u64 cpages;\n\t__u64 faults;\n};\n\nconst size_t size = 1 * 1024 * 1024 * 1024ul;\nconst size_t chunk_size = 2 * 1024 * 1024ul;\n\nint m\n---truncated---"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - Triggering requires local access — mmap of a hugetlb region plus DRM render-node ioctls to set up nouveau SVM and issue a GPU atomic fault (or the `/dev/hmm_dmirror` ioctl on CONFIG_TEST_HMM kernels). There is no network-reachable path to `make_device_exclusive_range()`.\nAC:L - No race or memory-layout luck is involved; the attacker deterministically creates the hugetlb VMA and directs a GPU atomic access at it, and `pmd_trans_huge()` is unconditionally true for a PMD-sized hugetlb entry. Nouveau SVM is enabled in mainstream distro kernels and hugepage pools are standard on GPU/HPC/database hosts, so nothing required is outside the attacker's control.\nPR:L - `NOUVEAU_SVM_INIT`/`NOUVEAU_SVM_BIND` are `DRM_RENDER_ALLOW`, reachable by any user who can open `/dev/dri/renderD*` (world- or render-group accessible on desktops and GPU compute nodes), and `mmap(MAP_ANONYMOUS|MAP_HUGETLB)` requires no capability. A plain unprivileged local account suffices.\nUI:N - The attacking process performs every step itself — allocating the hugetlb mapping, binding SVM, and issuing the GPU atomic operation. No victim action or cooperation is needed.\nS:U - The page-table and hugetlb-folio corruption occurs within the kernel that already manages the attacking process, yielding standard local privilege escalation. No VM, IOMMU, or other security-authority boundary is crossed.\nC:H - After the PMD is replaced with a normal PTE table, `hugetlb_wp()` calls `copy_user_large_folio()` with the page-table page as the source, copying raw PTE contents — physical addresses defeating KASLR/physmap randomization — into an attacker-readable hugepage. The subsequent use-after-free on the freed page table gives a broad kernel read primitive.\nI:H - `folio_put()`/`hugetlb_remove_rmap()` are applied to a page-table page that is still installed in the process's page tables, so it is freed and reallocated while live, giving stale PTEs that translate to arbitrary physical memory — a direct arbitrary-write primitive. Hugetlb folio refcount underflow and corrupted RSS/mapcount accounting compound this.\nA:H - The commit's own trace shows an immediate `kernel BUG at mm/page_table_check.c:87` (`Oops: invalid opcode`) from `pmdp_huge_clear_flush()` under CONFIG_PAGE_TABLE_CHECK. Without that debug option the resulting page-table corruption and refcount underflow reliably panic the kernel, and the trigger is repeatable at will."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "mm/gup.c"
                    ],
                    "versions": [
                        {
                            "version": "9cb28da54643ad464c47585cd5866c30b0218e67",
                            "lessThan": "2e877ff3492267def06dd50cb165dc9ab8838e7d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "9cb28da54643ad464c47585cd5866c30b0218e67",
                            "lessThan": "48d28417c66cce2f3b0ba773fcb6695a56eff220",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "9cb28da54643ad464c47585cd5866c30b0218e67",
                            "lessThan": "fd900832e8440046627b60697687ab5d04398008",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "9cb28da54643ad464c47585cd5866c30b0218e67",
                            "lessThan": "8977752c8056a6a094a279004a49722da15bace3",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "mm/gup.c"
                    ],
                    "versions": [
                        {
                            "version": "6.10",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.10",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.23",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.13.11",
                            "lessThanOrEqual": "6.13.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.14.2",
                            "lessThanOrEqual": "6.14.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.15",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.10",
                                    "versionEndExcluding": "6.12.23"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.10",
                                    "versionEndExcluding": "6.13.11"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.10",
                                    "versionEndExcluding": "6.14.2"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.10",
                                    "versionEndExcluding": "6.15"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/2e877ff3492267def06dd50cb165dc9ab8838e7d"
                },
                {
                    "url": "https://git.kernel.org/stable/c/48d28417c66cce2f3b0ba773fcb6695a56eff220"
                },
                {
                    "url": "https://git.kernel.org/stable/c/fd900832e8440046627b60697687ab5d04398008"
                },
                {
                    "url": "https://git.kernel.org/stable/c/8977752c8056a6a094a279004a49722da15bace3"
                }
            ],
            "title": "mm/gup: reject FOLL_SPLIT_PMD with hugetlb VMAs",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}