CVE-2025-37818
published 2025-05-08CVE-2025-37818: In the Linux kernel, the following vulnerability has been resolved: LoongArch: Return NULL from huge_pte_offset() for invalid PMD LoongArch's huge_pte_offset()…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
6.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Return NULL from huge_pte_offset() for invalid PMD
LoongArch's huge_pte_offset() currently returns a pointer to a PMD slot
even if the underlying entry points to invalid_pte_table (indicating no
mapping). Callers like smaps_hugetlb_range() fetch this invalid entry
value (the address of invalid_pte_table) via this pointer.
The generic is_swap_pte() check then incorrectly identifies this address
as a swap entry on LoongArch, because it satisfies the "!pte_present()
&& !pte_none()" conditions. This misinterpretation, combined with a
coincidental match by is_migration_entry() on the address bits, leads to
kernel crashes in pfn_swap_entry_to_page().
Fix this at the architecture level by modifying huge_pte_offset() to
check the PMD entry's content using pmd_none() before returning. If the
entry is invalid (i.e., it points to invalid_pte_table), return NULL
instead of the pointer to the slot.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 6.1.137-1 (bookworm) | linux 6.1.137-1 (bookworm) |
| debian | linux-6.1 | < linux 6.1.137-1 (bookworm) | linux 6.1.137-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= fa96b57c149061f71a70bd6582d995f6424fbbf4 < 34256805720993e37adf6127371a1265aea8376a | 34256805720993e37adf6127371a1265aea8376a |
| linux | linux | >= fa96b57c149061f71a70bd6582d995f6424fbbf4 < 2ca9380b12711afe95b3589bd82b59623b3c96b3 | 2ca9380b12711afe95b3589bd82b59623b3c96b3 |
| linux | linux | >= fa96b57c149061f71a70bd6582d995f6424fbbf4 < 51424fd171cee6a33f01f7c66b8eb23ac42289d4 | 51424fd171cee6a33f01f7c66b8eb23ac42289d4 |
| linux | linux | >= fa96b57c149061f71a70bd6582d995f6424fbbf4 < b49f085cd671addbda4802d6b9382513f7dd0f30 | b49f085cd671addbda4802d6b9382513f7dd0f30 |
| linux | linux | >= fa96b57c149061f71a70bd6582d995f6424fbbf4 < bd51834d1cf65a2c801295d230c220aeebf87a73 | bd51834d1cf65a2c801295d230c220aeebf87a73 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.1.137-1 | 6.1.137-1 |
| linux | linux_kernel | >= 0 < 6.12.27-1 | 6.12.27-1 |
| linux | linux_kernel | >= 0 < 6.12.27-1 | 6.12.27-1 |
| linux | linux_kernel | >= 5.19 < 6.1.136 | 6.1.136 |
| linux | linux_kernel | >= 6.13 < 6.14.5 | 6.14.5 |
| linux | linux_kernel | >= 6.2 < 6.6.89 | 6.6.89 |
| linux | linux_kernel | >= 6.7 < 6.12.26 | 6.12.26 |
| msrc | azl3_kernel_6.6.85.1-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_kernel_6.6.92.2-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
LoongArch: Return NULL from huge_pte_offset() for invalid PMD
vendor_msrc·2025-05-13·CVSS 5.5
CVE-2025-37818 [MEDIUM] CWE-476 LoongArch: Return NULL from huge_pte_offset() for invalid PMD
LoongArch: Return NULL from huge_pte_offset() for invalid PMD
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https:/
Red Hat
kernel: LoongArch: Return NULL from huge_pte_offset() for invalid PMD
vendor_redhat·2025-05-08·CVSS 5.5
CVE-2025-37818 [MEDIUM] CWE-400 kernel: LoongArch: Return NULL from huge_pte_offset() for invalid PMD
kernel: LoongArch: Return NULL from huge_pte_offset() for invalid PMD
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Return NULL from huge_pte_offset() for invalid PMD
LoongArch's huge_pte_offset() currently returns a pointer to a PMD slot
even if the underlying entry points to invalid_pte_table (indicating no
mapping). Callers like smaps_hugetlb_range() fetch this invalid entry
value (the address of invalid_pte_table) via this pointer.
The generic is_swap_pte() check then incorrectly identifies this address
as a swap entry on LoongArch, because it satisfies the "!pte_present()
&& !pte_none()" conditions. This misinterpretation, combined with a
coincidental match by is_migration_entry() on the address bits, leads to
kernel crashes in pfn_swap_entry_to_page(
Debian
CVE-2025-37818: linux - In the Linux kernel, the following vulnerability has been resolved: LoongArch: ...
vendor_debian·2025·CVSS 5.5
CVE-2025-37818 [MEDIUM] CVE-2025-37818: linux - In the Linux kernel, the following vulnerability has been resolved: LoongArch: ...
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Return NULL from huge_pte_offset() for invalid PMD LoongArch's huge_pte_offset() currently returns a pointer to a PMD slot even if the underlying entry points to invalid_pte_table (indicating no mapping). Callers like smaps_hugetlb_range() fetch this invalid entry value (the address of invalid_pte_table) via this pointer. The generic is_swap_pte() check then incorrectly identifies this address as a swap entry on LoongArch, because it satisfies the "!pte_present() && !pte_none()" conditions. This misinterpretation, combined with a coincidental match by is_migration_entry() on the address bits, leads to kernel crashes in pfn_swap_entry_to_page(). Fix this at the architecture level by modifying huge_pte_offset() to
OSV
CVE-2025-37818: In the Linux kernel, the following vulnerability has been resolved: LoongArch: Return NULL from huge_pte_offset() for invalid PMD LoongArch's huge_pte
osv·2025-05-08·CVSS 5.5
CVE-2025-37818 [MEDIUM] CVE-2025-37818: In the Linux kernel, the following vulnerability has been resolved: LoongArch: Return NULL from huge_pte_offset() for invalid PMD LoongArch's huge_pte
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Return NULL from huge_pte_offset() for invalid PMD LoongArch's huge_pte_offset() currently returns a pointer to a PMD slot even if the underlying entry points to invalid_pte_table (indicating no mapping). Callers like smaps_hugetlb_range() fetch this invalid entry value (the address of invalid_pte_table) via this pointer. The generic is_swap_pte() check then incorrectly identifies this address as a swap entry on LoongArch, because it satisfies the "!pte_present() && !pte_none()" conditions. This misinterpretation, combined with a coincidental match by is_migration_entry() on the address bits, leads to kernel crashes in pfn_swap_entry_to_page(). Fix this at the architecture level by modifying huge_pte_offset() to
GHSA
GHSA-4q4q-jv3m-fqjr: In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Return NULL from huge_pte_offset() for invalid PMD
LoongArch's huge_p
ghsa_unreviewed·2025-05-08
CVE-2025-37818 [MEDIUM] CWE-476 GHSA-4q4q-jv3m-fqjr: In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Return NULL from huge_pte_offset() for invalid PMD
LoongArch's huge_p
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Return NULL from huge_pte_offset() for invalid PMD
LoongArch's huge_pte_offset() currently returns a pointer to a PMD slot
even if the underlying entry points to invalid_pte_table (indicating no
mapping). Callers like smaps_hugetlb_range() fetch this invalid entry
value (the address of invalid_pte_table) via this pointer.
The generic is_swap_pte() check then incorrectly identifies this address
as a swap entry on LoongArch, because it satisfies the "!pte_present()
&& !pte_none()" conditions. This misinterpretation, combined with a
coincidental match by is_migration_entry() on the address bits, leads to
kernel crashes in pfn_swap_entry_to_page().
Fix this at the architecture level by modifying huge_pte_offset(
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2ca9380b12711afe95b3589bd82b59623b3c96b3https://git.kernel.org/stable/c/34256805720993e37adf6127371a1265aea8376ahttps://git.kernel.org/stable/c/51424fd171cee6a33f01f7c66b8eb23ac42289d4https://git.kernel.org/stable/c/b49f085cd671addbda4802d6b9382513f7dd0f30https://git.kernel.org/stable/c/bd51834d1cf65a2c801295d230c220aeebf87a73https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
2025-05-08
Published