In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a… (CVE-2025-38085)
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a reference on a page table that may have previously been shared across processes, potentially turning it into a normal page table used in another process in which unrelated VMAs can afterwards be installed. If this happens in the middle of a concurrent gup_fast(), gup_fast() could end up walking the page tables of another process. While I don't see any way in which that immediately leads to kernel memory corruption, it is really weird and unexpected. Fix it with an explicit broadcast IPI through tlb_remove_table_sync_one(), just like we do in khugepaged when removing page tables for a THP collapse.
AI Analysis
Technical Summary
The Red Hat kernel-rt security update addresses four vulnerabilities: a race condition in the huge page management code (huge_pmd_unshare() vs GUP-fast race, CVE-2025-38085), a buffer size miscalculation causing out-of-bounds reads in the rtw88 wifi driver (CVE-2025-38159), and use-after-free vulnerabilities in the Bluetooth hci_core subsystem (vhci_flush(), CVE-2025-38250) and the TIPC connection close function (tipc_conn_close(), CVE-2025-38464). These issues could lead to memory corruption or information disclosure. The update is available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and Extended Life Cycle 9.2. The advisory references official Red Hat errata RHSA-2025:15224 and provides instructions for applying the update and rebooting the system.
Potential Impact
The vulnerabilities affect the kernel-rt packages used in Red Hat Enterprise Linux 9.2, potentially allowing memory corruption or information disclosure due to race conditions, out-of-bounds reads, and use-after-free bugs. The impact is rated as moderate by Red Hat Product Security. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
An official security update is available from Red Hat (RHSA-2025:15224) that addresses these vulnerabilities. Users should apply the kernel-rt update for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and Extended Life Cycle 9.2 as provided by Red Hat and reboot the system for the changes to take effect. Refer to https://access.redhat.com/articles/11258 for detailed update instructions.
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a… (CVE-2025-38085)
Description
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a reference on a page table that may have previously been shared across processes, potentially turning it into a normal page table used in another process in which unrelated VMAs can afterwards be installed. If this happens in the middle of a concurrent gup_fast(), gup_fast() could end up walking the page tables of another process. While I don't see any way in which that immediately leads to kernel memory corruption, it is really weird and unexpected. Fix it with an explicit broadcast IPI through tlb_remove_table_sync_one(), just like we do in khugepaged when removing page tables for a THP collapse.
CVSS v3.1
Score 7.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat kernel-rt security update addresses four vulnerabilities: a race condition in the huge page management code (huge_pmd_unshare() vs GUP-fast race, CVE-2025-38085), a buffer size miscalculation causing out-of-bounds reads in the rtw88 wifi driver (CVE-2025-38159), and use-after-free vulnerabilities in the Bluetooth hci_core subsystem (vhci_flush(), CVE-2025-38250) and the TIPC connection close function (tipc_conn_close(), CVE-2025-38464). These issues could lead to memory corruption or information disclosure. The update is available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and Extended Life Cycle 9.2. The advisory references official Red Hat errata RHSA-2025:15224 and provides instructions for applying the update and rebooting the system.
Potential Impact
The vulnerabilities affect the kernel-rt packages used in Red Hat Enterprise Linux 9.2, potentially allowing memory corruption or information disclosure due to race conditions, out-of-bounds reads, and use-after-free bugs. The impact is rated as moderate by Red Hat Product Security. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
An official security update is available from Red Hat (RHSA-2025:15224) that addresses these vulnerabilities. Users should apply the kernel-rt update for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and Extended Life Cycle 9.2 as provided by Red Hat and reboot the system for the changes to take effect. Refer to https://access.redhat.com/articles/11258 for detailed update instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:15224
- Cve Count
- 4
- Additional Cves
- ["CVE-2025-38159","CVE-2025-38250","CVE-2025-38464"]
Threat ID: 6a3caf124853345fc153d78b
Added to database: 06/25/2026, 04:31:14 UTC
Last enriched: 06/25/2026, 04:47:14 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.