{
  "schema_version": "1.6.1",
  "id": "RPI-CVE-2025-39725",
  "modified": "2026-10-07T14:35:31Z",
  "upstream": [
    "CVE-2025-39725"
  ],
  "published": "2025-09-05T17:27:47Z",
  "summary": "mm/vmscan: fix hwpoisoned large folio handling in shrink_folio_list",
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmscan: fix hwpoisoned large folio handling in shrink_folio_list\n\nIn shrink_folio_list(), the hwpoisoned folio may be large folio, which\ncan't be handled by unmap_poisoned_folio().  For THP, try_to_unmap_one()\nmust be passed with TTU_SPLIT_HUGE_PMD to split huge PMD first and then\nretry.  Without TTU_SPLIT_HUGE_PMD, we will trigger null-ptr deref of\npvmw.pte.  Even we passed TTU_SPLIT_HUGE_PMD, we will trigger a\nWARN_ON_ONCE due to the page isn't in swapcache.\n\nSince UCE is rare in real world, and race with reclaimation is more rare,\njust skipping the hwpoisoned large folio is enough.  memory_failure() will\nhandle it if the UCE is triggered again.\n\nThis happens when memory reclaim for large folio races with\nmemory_failure(), and will lead to kernel panic.  The race is as\nfollows:\n\ncpu0      cpu1\n shrink_folio_list memory_failure\n  TestSetPageHWPoison\n  unmap_poisoned_folio\n  --> trigger BUG_ON due to\n  unmap_poisoned_folio couldn't\n   handle large folio\n\n[tujinjiang@huawei.com: add comment to unmap_poisoned_folio()]",
  "affected": [
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:12",
        "name": "linux"
      },
      "versions": [
        "1:6.12.34-1+rpt1~bookworm"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-2712",
            "binary_version": "1:6.12.34-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v6",
            "binary_version": "1:6.12.34-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v7",
            "binary_version": "1:6.12.34-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v7l",
            "binary_version": "1:6.12.34-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v8",
            "binary_version": "1:6.12.34-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v8-rt",
            "binary_version": "1:6.12.34-1+rpt1~bookworm"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.12.34-1+rpt1~bookworm": {
            "linux_commit": "8f77e03530f65209a377d25023e912b288e039cd",
            "upstream_version": "6.12.34",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.41"
          }
        }
      }
    },
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:13",
        "name": "linux"
      },
      "versions": [
        "1:6.12.34-1+rpt1"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-2712",
            "binary_version": "1:6.12.34-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v6",
            "binary_version": "1:6.12.34-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v7",
            "binary_version": "1:6.12.34-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v8",
            "binary_version": "1:6.12.34-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v8-rt",
            "binary_version": "1:6.12.34-1+rpt1"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.12.34-1+rpt1": {
            "linux_commit": "8f77e03530f65209a377d25023e912b288e039cd",
            "upstream_version": "6.12.34",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.41"
          }
        }
      }
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-39725"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/656eaddbc952e1baae2f69281c22debe22140312"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/c1101113d45838a823188ae25c61af97552a28ae"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/9f1e8cd0b7c4c944e9921b52a6661b5eda2705ab"
    }
  ],
  "database_specific": {
    "source": "https://git.kernel.org/pub/scm/linux/security/vulns.git",
    "upstream_modified": "2026-05-24T06:48:58Z"
  }
}
