Skip to main content
EPSS 0.1%top 97%

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a… (CVE-2025-38085)

0
Medium
Published: 06/28/2025 (06/28/2025, 08:15:00 UTC)
Source: GCVE Database
Product: linux

Description

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a reference on a page table that may have previously been shared across processes, potentially turning it into a normal page table used in another process in which unrelated VMAs can afterwards be installed. If this happens in the middle of a concurrent gup_fast(), gup_fast() could end up walking the page tables of another process. While I don't see any way in which that immediately leads to kernel memory corruption, it is really weird and unexpected. Fix it with an explicit broadcast IPI through tlb_remove_table_sync_one(), just like we do in khugepaged when removing page tables for a THP collapse.

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

Affected versions
Red HatRed Hat Enterprise LinuxRed Hat Enterprise Linux Real Time E4S (v.9.2)Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)src<5.15.0-1092.99~20.04.1<5.15.0-1096.105~20.04.1<5.15.0-1092.101~20.04.1<5.15.0-156.166~20.04.1<5.15.0-1086.89~20.04.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/25/2026, 04:47:14 UTC

Technical Analysis

The Red Hat kernel-rt security update addresses four vulnerabilities: a race condition in the huge page management code (huge_pmd_unshare() vs GUP-fast race, CVE-2025-38085), a buffer size miscalculation causing out-of-bounds reads in the rtw88 wifi driver (CVE-2025-38159), and use-after-free vulnerabilities in the Bluetooth hci_core subsystem (vhci_flush(), CVE-2025-38250) and the TIPC connection close function (tipc_conn_close(), CVE-2025-38464). These issues could lead to memory corruption or information disclosure. The update is available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and Extended Life Cycle 9.2. The advisory references official Red Hat errata RHSA-2025:15224 and provides instructions for applying the update and rebooting the system.

Potential Impact

The vulnerabilities affect the kernel-rt packages used in Red Hat Enterprise Linux 9.2, potentially allowing memory corruption or information disclosure due to race conditions, out-of-bounds reads, and use-after-free bugs. The impact is rated as moderate by Red Hat Product Security. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

An official security update is available from Red Hat (RHSA-2025:15224) that addresses these vulnerabilities. Users should apply the kernel-rt update for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and Extended Life Cycle 9.2 as provided by Red Hat and reboot the system for the changes to take effect. Refer to https://access.redhat.com/articles/11258 for detailed update instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:15224
Cve Count
4
Additional Cves
["CVE-2025-38159","CVE-2025-38250","CVE-2025-38464"]

Threat ID: 6a3caf124853345fc153d78b

Added to database: 06/25/2026, 04:31:14 UTC

Last enriched: 06/25/2026, 04:47:14 UTC

Last updated: 09/10/2026, 19:36:50 UTC

Views: 74

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses