CVE-2025-38029

Aliases:UBUNTU-CVE-2025-38029DEBIAN-CVE-2025-38029CGA-22ff-9346-q79mCGA-22qg-xfmw-8693CGA-266x-6wjf-fr2qCGA-28pc-cp49-gw37CGA-2hm9-69x5-v2rhCGA-2p8f-fr65-xj7gCGA-2x3v-4v4f-wxhwCGA-2xg5-hfmj-xghvCGA-335j-58j8-58p5CGA-3f3p-w9qw-g225CGA-3j94-fcv2-742vCGA-3rvh-798g-cvfxCGA-4c2g-9xg2-qggrCGA-4fj8-rw5w-53r8CGA-4gxj-7j7c-vg8cCGA-4q2r-9g64-7fcxCGA-5922-33gf-5882CGA-5c2f-q983-94vgCGA-5f4r-j4r6-7hxwCGA-6463-6p47-9qwfCGA-66h6-2rj6-532jCGA-6fgw-w6h4-q7qcCGA-6h2j-9ppg-q3j6CGA-6x2c-c3f7-8w94CGA-74w7-rc2v-v8cqCGA-7f6h-v2v8-ggj9CGA-7p62-r388-rrvrCGA-7pv4-797g-94qrCGA-7qf5-8mhp-79gwCGA-7r99-2v6q-m4hhCGA-7rg9-h6h5-8w3mCGA-7rj4-h439-m77gCGA-7xrj-x53x-69x7CGA-82cp-vm78-qc7cCGA-85rq-fxq8-5mcmCGA-8823-f5gq-5vh9CGA-8p73-w8rq-v76wCGA-8q23-5xmh-mv4rCGA-8rhj-86q8-78wfCGA-8v6m-m5x3-m4jgCGA-967p-r5q4-cgwpCGA-97x9-38x3-66c4CGA-9j54-x69r-vm7cCGA-9x62-7645-5h2rCGA-c2jx-hw42-g564CGA-c36r-m58q-4mj6CGA-c4gr-4w2v-8q46CGA-c557-f4qm-jgfjCGA-cpw6-f85v-c9wpCGA-cwhv-qhqr-j3cqCGA-fgj8-4qww-jjg9CGA-fjf5-3qvh-w4rcCGA-fm2p-6c9f-hm98CGA-fxx7-992m-hmjmCGA-g4mp-8xhq-h59qCGA-gj8g-2qj9-h2jmCGA-grc7-4h6m-h4w2CGA-gxgr-8663-hxvxCGA-h28g-fhqq-wf38CGA-h3rw-5c8r-4wcxCGA-h945-jxr6-w979CGA-h9fw-prc6-pmw8CGA-hh56-7phh-r579CGA-hv6r-4qqr-4q7jCGA-j85r-g65r-h6wqCGA-jcwq-f4qg-f6j9CGA-jqq6-2w3g-r8g5CGA-jvg7-42mx-6mqgCGA-jxff-2822-x6g7CGA-jxv2-26p2-3j8rCGA-m3p8-qch8-wg3gCGA-m6wc-45mq-72r4CGA-mcf3-xjc6-qhvjCGA-mhpg-2798-7gfxCGA-mjrm-q3rh-pq5hCGA-mpm7-hgj6-vfp2CGA-mpxr-9rxh-mf2xCGA-mqxm-7pr3-699gCGA-mvwp-c5w5-w25fCGA-mwg9-pj4c-6w2cCGA-p4cv-wj58-m3fgCGA-p8mj-rx4p-3cf9CGA-pfrj-r94j-5hrhCGA-pfwf-r8qw-mp3rCGA-pm3j-jvjr-ccrxCGA-pw7x-vxx7-3jj9CGA-q5j6-79wh-8x48CGA-q8j7-g893-2j32CGA-q954-5v9w-7h37CGA-qcmg-p586-2jwgCGA-qv7c-fqx6-qh5mCGA-r4rc-fvfq-2r28CGA-r75g-7779-cpfpCGA-r86q-vrmg-rcpgCGA-r89p-cvrv-h5xfCGA-r9pf-x6v5-cxmqCGA-rh46-9fg4-q2r6CGA-rmr6-gg66-jfmfCGA-rrw8-wgq3-634qCGA-v4q4-x2mj-qrrvCGA-v53x-79wx-qvggCGA-v6xc-rmq9-m29vCGA-vr9x-28fp-6rp6CGA-vw7p-vxgf-wpmhCGA-w3mj-863p-hpw5CGA-w585-377c-26rmCGA-w85q-x3j7-4chjCGA-wg3v-g442-cq57CGA-whwv-8xc6-9jrpCGA-wp9v-fxmq-p8mpCGA-wr66-227g-qq4fCGA-wvf3-fjgx-x77wCGA-wx79-4j38-mgr5CGA-x7v5-7rfh-fc9pCGA-xh62-69xh-vqjgCGA-xj3m-gw8f-58q3CGA-xqjg-6ccm-7cm7CGA-xvpc-268g-3f23
Advisory lineage Upstream: 0 Downstream: 9
Analyzed
Published: 18 Jun 2025, 09:33
Last modified:11 May 2026, 21:19

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.15% LOW
0% probability +0.12%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Jun 2025, 09:33
Published
Vulnerability first disclosed
11 May 2026, 21:19
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: kasan: avoid sleepable page allocation from atomic context apply_to_pte_range() enters the lazy MMU mode and then invokes kasan_populate_vmalloc_pte() callback on each page table walk iteration. However, the callback can go into sleep when trying to allocate a single page, e.g. if an architecutre disables preemption on lazy MMU mode enter. On s390 if make arch_enter_lazy_mmu_mode() -> preempt_enable() and arch_leave_lazy_mmu_mode() -> preempt_disable(), such crash occurs: [ 0.663336] BUG: sleeping function called from invalid context at ./include/linux/sched/mm.h:321 [ 0.663348] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 2, name: kthreadd [ 0.663358] preempt_count: 1, expected: 0 [ 0.663366] RCU nest depth: 0, expected: 0 [ 0.663375] no locks held by kthreadd/2. [ 0.663383] Preemption disabled at: [ 0.663386] [<0002f3284cbb4eda>] apply_to_pte_range+0xfa/0x4a0 [ 0.663405] CPU: 0 UID: 0 PID: 2 Comm: kthreadd Not tainted 6.15.0-rc5-gcc-kasan-00043-gd76bb1ebb558-dirty #162 PREEMPT [ 0.663408] Hardware name: IBM 3931 A01 701 (KVM/Linux) [ 0.663409] Call Trace: [ 0.663410] [<0002f3284c385f58>] dump_stack_lvl+0xe8/0x140 [ 0.663413] [<0002f3284c507b9e>] __might_resched+0x66e/0x700 [ 0.663415] [<0002f3284cc4f6c0>] __alloc_frozen_pages_noprof+0x370/0x4b0 [ 0.663419] [<0002f3284ccc73c0>] alloc_pages_mpol+0x1a0/0x4a0 [ 0.663421] [<0002f3284ccc8518>] alloc_frozen_pages_noprof+0x88/0xc0 [ 0.663424] [<0002f3284ccc8572>] alloc_pages_noprof+0x22/0x120 [ 0.663427] [<0002f3284cc341ac>] get_free_pages_noprof+0x2c/0xc0 [ 0.663429] [<0002f3284cceba70>] kasan_populate_vmalloc_pte+0x50/0x120 [ 0.663433] [<0002f3284cbb4ef8>] apply_to_pte_range+0x118/0x4a0 [ 0.663435] [<0002f3284cbc7c14>] apply_to_pmd_range+0x194/0x3e0 [ 0.663437] [<0002f3284cbc99be>] __apply_to_page_range+0x2fe/0x7a0 [ 0.663440] [<0002f3284cbc9e88>] apply_to_page_range+0x28/0x40 [ 0.663442] [<0002f3284ccebf12>] kasan_populate_vmalloc+0x82/0xa0 [ 0.663445] [<0002f3284cc1578c>] alloc_vmap_area+0x34c/0xc10 [ 0.663448] [<0002f3284cc1c2a6>] __get_vm_area_node+0x186/0x2a0 [ 0.663451] [<0002f3284cc1e696>] __vmalloc_node_range_noprof+0x116/0x310 [ 0.663454] [<0002f3284cc1d950>] __vmalloc_node_noprof+0xd0/0x110 [ 0.663457] [<0002f3284c454b88>] alloc_thread_stack_node+0xf8/0x330 [ 0.663460] [<0002f3284c458d56>] dup_task_struct+0x66/0x4d0 [ 0.663463] [<0002f3284c45be90>] copy_process+0x280/0x4b90 [ 0.663465] [<0002f3284c460940>] kernel_clone+0xd0/0x4b0 [ 0.663467] [<0002f3284c46115e>] kernel_thread+0xbe/0xe0 [ 0.663469] [<0002f3284c4e440e>] kthreadd+0x50e/0x7f0 [ 0.663472] [<0002f3284c38c04a>] __ret_from_fork+0x8a/0xf0 [ 0.663475] [<0002f3284ed57ff2>] ret_from_fork+0xa/0x38 Instead of allocating single pages per-PTE, bulk-allocate the shadow memory prior to applying kasan_populate_vmalloc_pte() callback on a page range.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.15% Percentile: 4%

Affected Systems

  • chainguardlinux-aws-6.12

    < 6.12.62-r1 | < 6.12.78-r0 | < 6.12.71-r0 | < 6.12.76-r0 | < 6.12.65-r0 | < 6.12.63-r0 | < 6.12.62-r2 | < 6.12.74-r0 | < 6.12.60-r4 | < 6.12.68-r1 | < 6.12.67-r0 | < 6.12.77-r1 | < 6.12.77-r0 | < 6.12.68-r0 | < 6.12.77-r2 | < 6.12.69-r0 | < 6.12.57-r2 | < 6.12.80-r0 | < 6.12.70-r0 | < 6.12.65-r2 | < 6.12.65-r1 | < 6.12.72-r1 | < 6.12.72-r0 | < 6.12.74-r1 | < 6.12.66-r0 | < 6.12.62-r0

  • chainguardlinux-azure-6.12

    < 6.12.57-r2 | < 6.12.68-r0 | < 6.12.76-r0 | < 6.12.70-r0 | < 6.12.69-r0 | < 6.12.62-r0 | < 6.12.72-r0 | < 6.12.65-r4 | < 6.12.62-r1 | < 6.12.71-r0 | < 6.12.65-r1 | < 6.12.67-r0 | < 6.12.66-r0 | < 6.12.74-r0 | < 6.12.78-r0 | < 6.12.74-r1 | < 6.12.77-r2 | < 6.12.65-r3 | < 6.12.77-r0 | < 6.12.60-r4 | < 6.12.62-r2 | < 6.12.63-r0 | < 6.12.80-r0 | < 6.12.65-r2 | < 6.12.77-r1 | < 6.12.60-r3

  • chainguardlinux-gcp-6.12

    < 6.12.77-r1 | < 6.12.62-r0 | < 6.12.74-r0 | < 6.12.65-r2 | < 6.12.77-r2 | < 6.12.65-r0 | < 6.12.68-r1 | < 6.12.76-r0 | < 6.12.65-r1 | < 6.12.62-r2 | < 6.12.70-r0 | < 6.12.62-r1 | < 6.12.74-r1 | < 6.12.60-r3 | < 6.12.60-r4 | < 6.12.80-r0 | < 6.12.57-r2 | < 6.12.63-r0 | < 6.12.67-r0 | < 6.12.71-r0 | < 6.12.69-r0 | < 6.12.77-r0 | < 6.12.78-r0 | < 6.12.66-r0 | < 6.12.72-r0 | < 6.12.68-r0

  • chainguardlinux-qemu-6.12

    < 6.12.74-r0 | < 6.12.76-r0 | < 6.12.71-r0 | < 6.12.80-r0 | < 6.12.65-r1 | < 6.12.77-r0 | < 6.12.78-r0 | < 6.12.72-r0 | < 6.12.68-r0 | < 6.12.65-r2 | < 6.12.69-r0 | < 6.12.74-r1 | < 6.12.77-r2 | < 6.12.77-r1 | < 6.12.66-r0 | < 6.12.70-r0 | < 6.12.67-r0

  • chainguardlinux-vmware-6.12

    < 6.12.68-r0 | < 6.12.71-r0 | < 6.12.65-r1 | < 6.12.66-r0 | < 6.12.65-r2 | < 6.12.77-r1 | < 6.12.74-r1 | < 6.12.76-r0 | < 6.12.77-r0 | < 6.12.69-r0 | < 6.12.67-r0 | < 6.12.74-r0 | < 6.12.78-r0 | < 6.12.72-r0 | < 6.12.80-r0 | < 6.12.77-r2 | < 6.12.68-r1 | < 6.12.70-r0

  • debianlinux

    all | all | all | < 6.16.3-1

  • ubuntulinux

    all | all

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | all

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    all

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    < 6.14.0-1013.13~24.04.1

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    all

  • ubuntulinux-aws-fips

    all

  • ubuntulinux-azure

    all | all | all

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    all

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all | all | all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.17

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fde-6.8

    all

  • ubuntulinux-azure-fips

    all

  • ubuntulinux-azure-nvidia

    all

  • ubuntulinux-azure-nvidia-6.14

    < 6.14.0-1007.7

  • ubuntulinux-bluefield

    all

  • ubuntulinux-fips

    all

  • ubuntulinux-gcp

    all | all | all

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    all

  • ubuntulinux-gcp-5.19

    all

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.8

    all

Showing first 50 affected entries in server-rendered view.

References (13)