mm/huge_memory: fix NULL pointer deference when splitting folio
Published Dec 16, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.21%
Description
Commit c010d47f107f ("mm: thp: split huge page to any lower order pages") introduced an early check on the folio's order via mapping->flags before proceeding with the split work.
This check introduced a bug: for shmem folios in the swap cache and truncated folios, the mapping pointer can be NULL. Accessing mapping->flags in this state leads directly to a NULL pointer dereference.
This commit fixes the issue by moving the check for mapping != NULL before any attempt to access mapping->flags.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.9StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.9
- Version 6.12.61StatusunaffectedConstraints<=6.12.*
- Version 6.17.11StatusunaffectedConstraints<=6.17.*
- Version 6.18StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This crash can occur during memory management operations on shmem-backed huge pages, particularly during swap or truncation scenarios. The impact is denial of service.
References (9)
- https://access.redhat.com/security/cve/CVE-2025-68293 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2422797 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-203787 Advisory
- https://git.kernel.org/stable/c/592db83615a9f0164472ec789c2ed34ad35f732f
- https://git.kernel.org/stable/c/cff47b9e39a6abf03dde5f4f156f841b0c54bba0
- https://git.kernel.org/stable/c/d1b83fbacd4397a1d2f8c6b13427a8636ae2b307
- https://lore.kernel.org/linux-cve-announce/2025121640-CVE-2025-68293-ea76@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-68293
- https://www.cve.org/CVERecord?id=CVE-2025-68293
Change history (0)
No recorded changes yet.