
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38686 is a vulnerability discovered in the Linux kernel related to the userfaultfd mechanism. The vulnerability was disclosed on September 4, 2025, affecting the kernel's memory management subsystem, specifically in the handling of UFFDIO_MOVE operations when encountering PMD (Page Middle Directory) migration entries (NVD).
The vulnerability occurs in the userfaultfd subsystem when UFFDIOMOVE encounters a migration PMD entry. The issue arises when the system proceeds with obtaining a folio and accessing it even though the entry is swpentry_t, without proper validation. This technical oversight in the memory management code could lead to system instability (NVD).
The vulnerability could result in a system crash when specific memory operations are performed through the userfaultfd interface, potentially affecting system stability and availability (NVD).
The issue has been resolved in the Linux kernel through a patch that adds the missing check and allows splithugepmd() to handle migration entries properly. The fix also includes the removal of an unnecessary folio check (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."