Linux Kernel Out-of-Bounds Page Table Access Vulnerability in Batched Unmap Logic

Vulnerability

A vulnerability in the Linux kernel's memory management component can lead to out-of-bounds access in the page table during batched unmapping of large folios. This issue arises when the page table entries (PTEs) of a large folio extend beyond a single page table, potentially allowing for memory corruption. The vulnerability is present in the stable branch of the Linux kernel.

Impact

Exploitation of this vulnerability could lead to memory corruption by allowing the batched unmap logic to read past the end of a PTE table, creating a risk of accessing invalid memory regions.

Remediation

Users can upgrade to the latest version of the Linux kernel stable tree, where this vulnerability has been addressed.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
7.7
relevance
0.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.