CVE-2025-22045

Updated: 2025-11-10 02:22:26.071115

Description:

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs On the following path, flush_tlb_range() can be used for zapping normal PMD entries (PMD entries that point to page tables) together with the PTE entries in the pointed-to page table: collapse_pte_mapped_thp pmdp_collapse_flush flush_tlb_range The arm64 version of flush_tlb_range() has a comment describing that it can be used for page table removal, and does not use any last-level invalidation optimizations. Fix the X86 version by making it behave the same way. Currently, X86 only uses this information for the following two purposes, which I think means the issue doesn't have much impact: - In native_flush_tlb_multi() for checking if lazy TLB CPUs need to be IPI'd to avoid issues with speculative page table walks. - In Hyper-V TLB paravirtualization, again for lazy TLB stuff. The patch "x86/mm: only invalidate final translations with INVLPGB" which is currently under review (see <https://lore.kernel.org/all/20241230175550.4046587-13-riel@surriel.com/>) would probably be making the impact of this a lot worse.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-11-05 04:53:20 This is an x86-only, local attack that touches a kernel-internal TLB flush path during THP collapse/...
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-12-18 19:38:16
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-12-18 19:38:16
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-12-18 19:38:16
Oracle Linux 7 ELS kernel-uek 5.4.17 5.5 MEDIUM Released CLSA-2025:1757963029 2025-09-16 11:21:05
TuxCare 9.6 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-11-05 04:53:20 CVE-2025-22045 is an x86-only kernel bug in TLB invalidation during page‑table removal/THP collaps...
Ubuntu 18.04 ELS linux 4.15.0 5.5 MEDIUM Ignored 2025-08-23 06:48:51 Ignored due to low severity
Ubuntu 20.04 ELS linux 5.4.0 5.5 MEDIUM Ignored 2025-07-09 01:18:01 Ignored due to low severity