CVE-2025-38447
Linux Ubuntu vulnerability analysis and mitigation

Overview

CVE-2025-38447 is an out-of-bounds read vulnerability in the Linux kernel's memory management subsystem (mm/rmap) that occurs during batched unmap operations. The flaw exists in try_to_unmap_one(), where the batched unmap logic may read past the end of a PTE (Page Table Entry) table when a large folio's PTE mappings are not fully contained within a single page table. Affected versions include Linux kernel 6.15 through 6.15.6 and release candidates 6.16-rc1 through 6.16-rc5. The vulnerability was published on July 25, 2025, with a CVSS v3.1 base score of 7.1 (High) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read), triggered in the try_to_unmap_one() function within the kernel's reverse mapping (mm/rmap) subsystem. When a large folio's PTE mappings span across page table boundaries (i.e., not fully contained within a single page table), the batched unmap logic fails to cap its scan correctly, potentially reading memory beyond the end of the PTE table. The fix introduces a new helper function, folio_unmap_pte_batch(), which correctly calculates the safe batch size by enforcing boundaries at both the VMA (Virtual Memory Area) and PMD (Page Middle Directory) levels, and supports partial batching for any number of pages up to the safe maximum. The vulnerability is locally exploitable with low privileges and no user interaction required (Red Hat Bugzilla, Feedly).

Impact

Successful exploitation could allow a local attacker with low-privileged user access to read memory outside of intended bounds, resulting in high confidentiality impact and high availability impact, with no integrity impact. This could expose sensitive kernel memory contents or contribute to system instability. While the triggering scenario (large folios spanning page table boundaries) is described as rare, the fact that it is triggerable from userspace makes it a meaningful risk, particularly as a component in more complex privilege escalation or information disclosure attack chains (Red Hat Advisory, Feedly).

Exploitability

There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation for CVE-2025-38447. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).

Mitigation and workarounds

The Linux kernel project has released patches addressing this vulnerability. Users should upgrade to Linux kernel version 6.15.7 or later, or apply the fix included in 6.16-rc6 and later release candidates. The upstream patches are available at the kernel stable repository (commits 510fe9c15d07e765d96be9a9dc37e5057c6c09f4 and ddd05742b45b083975a0855ef6ebbf88cf1f532a). As a general mitigation, limiting local user access to affected systems reduces exposure until patches can be applied (Red Hat Bugzilla, Kernel Patch 1, Kernel Patch 2).

Additional resources


SourceThis report was generated using AI

Related Linux Ubuntu vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63343CRITICAL9.9
  • Linux Debian logoLinux Debian
  • incus
NoYesAug 21, 2026
CVE-2026-50538HIGH8.8
  • Linux Debian logoLinux Debian
  • veyon
NoYesAug 21, 2026
CVE-2026-53525HIGH7.4
  • Linux Debian logoLinux Debian
  • weechat
NoYesAug 21, 2026
CVE-2026-53524MEDIUM6.5
  • Linux Debian logoLinux Debian
  • weechat
NoYesAug 21, 2026
CVE-2026-44517MEDIUM6.3
  • Podman logoPodman
  • podman-machine
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management