Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's memory management related to transparent huge pages (mTHP) and swap handling has been identified. This issue can lead to a soft lockup, where the CPU becomes unresponsive for an extended period. The vulnerability arises when mTHP folios are swapped in, conflicting with readahead operations, causing a loop of failed allocations and retries. The problem has been observed in kernel version 6.15.0.
Exploitation of this vulnerability causes a soft lockup, where a CPU core becomes unresponsive for an extended period, potentially leading to degraded system performance or responsiveness.
The vulnerability can be reproduced by enabling mTHP, activating a large swap device (such as a 48G zram swap), and then creating a memory-intensive workload that reads and writes large amounts of data. This process can be monitored to observe the resulting soft lockup on the CPU.
Users can apply the latest kernel patches available in the Linux kernel stable repository to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.