cbcvebase.
CVE-2025-68231
published 2025-12-16

CVE-2025-68231: In the Linux kernel, the following vulnerability has been resolved: mm/mempool: fix poisoning order>0 pages with HIGHMEM The kernel test has reported: BUG…

PriorityP423high7.8
EPSS
0.17%
6.2th percentile
In the Linux kernel, the following vulnerability has been resolved: mm/mempool: fix poisoning order>0 pages with HIGHMEM The kernel test has reported: BUG: unable to handle page fault for address: fffba000 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present page *pde = 03171067 *pte = 00000000 Oops: Oops: 0002 [#1] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Tainted: G T 6.18.0-rc2-00031-gec7f31b2a2d3 #1 NONE a1d066dfe789f54bc7645c7989957d2bdee593ca Tainted: [T]=RANDSTRUCT Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 EIP: memset (arch/x86/include/asm/string_32.h:168 arch/x86/lib/memcpy_32.c:17) Code: a5 8b 4d f4 83 e1 03 74 02 f3 a4 83 c4 04 5e 5f 5d 2e e9 73 41 01 00 90 90 90 3e 8d 74 26 00 55 89 e5 57 56 89 c6 89 d0 89 f7 aa 89 f0 5e 5f 5d 2e e9 53 41 01 00 cc cc cc 55 89 e5 53 57 56 EAX: 0000006b EBX: 00000015 ECX: 001fefff EDX: 0000006b ESI: fffb9000 EDI: fffba000 EBP: c611fbf0 ESP: c611fbe8 DS: 007b ES: 007b FS: 0000 GS: 0000 SS: 0068 EFLAGS: 00010287 CR0: 80050033 CR2: fffba000 CR3: 0316e000 CR4: 00040690 Call Trace: poison_element (mm/mempool.c:83 mm/mempool.c:102) mempool_init_node (mm/mempool.c:142 mm/mempool.c:226) mempool_init_noprof (mm/mempool.c:250 (discriminator 1)) ? mempool_alloc_pages (mm/mempool.c:640) bio_integrity_initfn (block/bio-integrity.c:483 (discriminator 8)) ? mempool_alloc_pages (mm/mempool.c:640) do_one_initcall (init/main.c:1283) Christoph found out this is due to the poisoning code not dealing properly with CONFIG_HIGHMEM because only the first page is mapped but then the whole potentially high-order page is accessed. We could give up on HIGHMEM here, but it's straightforward to fix this with a loop that's mapping, poisoning or checking and unmapping individual pages.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= bdfedb76f4f5aa5e37380e3b71adee4a39f30fc6 < ea4131665107e66ece90e66bcec1a2f1246cbd41ea4131665107e66ece90e66bcec1a2f1246cbd41
linuxlinux>= bdfedb76f4f5aa5e37380e3b71adee4a39f30fc6 < 19de79aaea33ee1ea058c8711b3b2b4a7e4decd419de79aaea33ee1ea058c8711b3b2b4a7e4decd4
linuxlinux>= bdfedb76f4f5aa5e37380e3b71adee4a39f30fc6 < 6a13b56537e7b0d97f4bb74e8038ce471f9770d76a13b56537e7b0d97f4bb74e8038ce471f9770d7
linuxlinux>= bdfedb76f4f5aa5e37380e3b71adee4a39f30fc6 < a79e49e1704367b635edad1479db23d7cf1fb71aa79e49e1704367b635edad1479db23d7cf1fb71a
linuxlinux>= bdfedb76f4f5aa5e37380e3b71adee4a39f30fc6 < ec33b59542d96830e3c89845ff833cf7b25ef172ec33b59542d96830e3c89845ff833cf7b25ef172
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.10-16.17.10-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 4.1.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.106.17.10
linuxlinux_kernel>= 6.2.0 < 6.6.1186.6.118
linuxlinux_kernel>= 6.7.0 < 6.12.606.12.60
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv7.2HIGH
vendor_msrc7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.