cbcvebase.
CVE-2025-68293
published 2025-12-16

CVE-2025-68293: In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix NULL pointer deference when splitting folio Commit c010d47f107f ("mm…

PriorityP421high7.2
EPSS
0.18%
8.2th percentile
In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix NULL pointer deference when splitting folio Commit c010d47f107f ("mm: thp: split huge page to any lower order pages") introduced an early check on the folio's order via mapping->flags before proceeding with the split work. This check introduced a bug: for shmem folios in the swap cache and truncated folios, the mapping pointer can be NULL. Accessing mapping->flags in this state leads directly to a NULL pointer dereference. This commit fixes the issue by moving the check for mapping != NULL before any attempt to access mapping->flags.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.11-1 (forky)linux 6.17.11-1 (forky)
linuxlinux
linuxlinux>= c010d47f107f609b9f4d6a103b6dfc53889049e9 < 592db83615a9f0164472ec789c2ed34ad35f732f592db83615a9f0164472ec789c2ed34ad35f732f
linuxlinux>= c010d47f107f609b9f4d6a103b6dfc53889049e9 < d1b83fbacd4397a1d2f8c6b13427a8636ae2b307d1b83fbacd4397a1d2f8c6b13427a8636ae2b307
linuxlinux>= c010d47f107f609b9f4d6a103b6dfc53889049e9 < cff47b9e39a6abf03dde5f4f156f841b0c54bba0cff47b9e39a6abf03dde5f4f156f841b0c54bba0
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.11-16.17.11-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.13.0 < 6.17.116.17.11
linuxlinux_kernel>= 6.9.0 < 6.12.616.12.61

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.