Bug 2420416 (CVE-2025-40336)
| Summary: | CVE-2025-40336 kernel: drm/gpusvm: fix hmm_pfn_to_map_order() usage | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's GPU shared virtual memory (gpusvm) subsystem. When handling HMM (Heterogeneous Memory Management) ranges that partially cover a huge page (such as 2MB pages), the hmm_pfn_to_map_order() function may incorrectly map memory outside the intended range. This could result in mapping memory that is not mapped by the process's memory management, potentially exposing unauthorized memory regions or causing memory corruption.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2025-12-09 05:01:56 UTC
|