cbcvebase.
CVE-2025-21861
published 2025-03-12

CVE-2025-21861: In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() If…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.6th percentile
In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() If migration succeeded, we called folio_migrate_flags()->mem_cgroup_migrate() to migrate the memcg from the old to the new folio. This will set memcg_data of the old folio to 0. Similarly, if migration failed, memcg_data of the dst folio is left unset. If we call folio_putback_lru() on such folios (memcg_data == 0), we will add the folio to be freed to the LRU, making memcg code unhappy. Running the hmm selftests: # ./hmm-tests ... # RUN hmm.hmm_device_private.migrate ... [ 102.078007][T14893] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x7ff27d200 pfn:0x13cc00 [ 102.079974][T14893] anon flags: 0x17ff00000020018(uptodate|dirty|swapbacked|node=0|zone=2|lastcpupid=0x7ff) [ 102.082037][T14893] raw: 017ff00000020018 dead000000000100 dead000000000122 ffff8881353896c9 [ 102.083687][T14893] raw: 00000007ff27d200 0000000000000000 00000001ffffffff 0000000000000000 [ 102.085331][T14893] page dumped because: VM_WARN_ON_ONCE_FOLIO(!memcg && !mem_cgroup_disabled()) [ 102.087230][T14893] ------------[ cut here ]------------ [ 102.088279][T14893] WARNING: CPU: 0 PID: 14893 at ./include/linux/memcontrol.h:726 folio_lruvec_lock_irqsave+0x10e/0x170 [ 102.090478][T14893] Modules linked in: [ 102.091244][T14893] CPU: 0 UID: 0 PID: 14893 Comm: hmm-tests Not tainted 6.13.0-09623-g6c216bc522fd #151 [ 102.093089][T14893] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 [ 102.094848][T14893] RIP: 0010:folio_lruvec_lock_irqsave+0x10e/0x170 [ 102.096104][T14893] Code: ... [ 102.099908][T14893] RSP: 0018:ffffc900236c37b0 EFLAGS: 00010293 [ 102.101152][T14893] RAX: 0000000000000000 RBX: ffffea0004f30000 RCX: ffffffff8183f426 [ 102.102684][T14893] RDX: ffff8881063cb880 RSI: ffffffff81b8117f RDI: ffff8881063cb880 [ 102.104227][T14893] RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 8763cb45ab967a92a5ee49e9c544c0f0ea90e2d6 < 61fa824e304ed162fe965f64999068e6fcff205961fa824e304ed162fe965f64999068e6fcff2059
linuxlinux>= 8763cb45ab967a92a5ee49e9c544c0f0ea90e2d6 < 64397b0cb7c09e3ef3f9f5c7c17299c4eebd387564397b0cb7c09e3ef3f9f5c7c17299c4eebd3875
linuxlinux>= 8763cb45ab967a92a5ee49e9c544c0f0ea90e2d6 < 4f52f7c50f5b6f5eeb06823e21fe546d90f9c5954f52f7c50f5b6f5eeb06823e21fe546d90f9c595
linuxlinux>= 8763cb45ab967a92a5ee49e9c544c0f0ea90e2d6 < 20fb6fc51863fbff7868de8b5f6d249d2094df1f20fb6fc51863fbff7868de8b5f6d249d2094df1f
linuxlinux>= 8763cb45ab967a92a5ee49e9c544c0f0ea90e2d6 < 78f579cb7d825134e071a1714d8d0c4fd0ffe45978f579cb7d825134e071a1714d8d0c4fd0ffe459
linuxlinux>= 8763cb45ab967a92a5ee49e9c544c0f0ea90e2d6 < 3f9240d59e9a95d19f06120bfd1d0e681c6c0ac73f9240d59e9a95d19f06120bfd1d0e681c6c0ac7
linuxlinux>= 8763cb45ab967a92a5ee49e9c544c0f0ea90e2d6 < 069dd21ea8262204f94737878389c2815a054a9e069dd21ea8262204f94737878389c2815a054a9e
linuxlinux>= 8763cb45ab967a92a5ee49e9c544c0f0ea90e2d6 < 41cddf83d8b00f29fd105e7a0777366edc69a5cf41cddf83d8b00f29fd105e7a0777366edc69a5cf
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.17-16.12.17-1
linuxlinux_kernel>= 0 < 6.12.17-16.12.17-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 4.14 < 6.12.176.12.17
linuxlinux_kernel>= 6.13 < 6.13.56.13.5
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0
ubuntulinux-azure-5.15

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.