Back

MEDIUM

mm/huge_memory: fix NULL pointer deference when splitting folio

Published Dec 16, 2025

Description

Commit c010d47f107f ("mm: thp: split huge page to any lower order pages") introduced an early check on the folio's order via mapping->flags before proceeding with the split work.

This check introduced a bug: for shmem folios in the swap cache and truncated folios, the mapping pointer can be NULL. Accessing mapping->flags in this state leads directly to a NULL pointer dereference.

This commit fixes the issue by moving the check for mapping != NULL before any attempt to access mapping->flags.

Affected products

Remediation

Red Hat statement

This crash can occur during memory management operations on shmem-backed huge pages, particularly during swap or truncation scenarios. The impact is denial of service.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Dec 16, 2025
Updated May 11, 2026
Reserved Dec 16, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 16, 2025
ENISA EUVD
Assigner Linux
Published Dec 16, 2025
Updated May 11, 2026
Exploited since n/a
EUVD-2025-203787