CVE-2025-68179
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68179 is a Linux kernel vulnerability affecting s390 architecture systems where enabling HugeTLB Vmemmap Optimization (HVO) leads to reproducible kernel crashes and potential data corruption. The flaw was introduced when ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP was enabled for s390, which is architecturally incompatible with s390's strict page table entry replacement rules. It affects Linux kernel versions from commit 00a34d5a99c0 up to the fixes applied in stable branches. The vulnerability was published on December 16, 2025, with an EPSS score of 0.00018 (very low exploitation probability) and no CVSS base score has been assigned (Feedly, EUVD).

Technical details

The root cause is an architectural incompatibility (CWE-665: Improper Initialization) between the HugeTLB Vmemmap Optimization (HVO) subsystem and the s390 memory management architecture. On s390, it is forbidden to directly replace an active/valid page table entry with another valid entry — the transition must go through an invalid state using special instructions such as ipte, idte, crdte, or cspg. The HVO code modifies kernel page tables without following this protocol and without flushing corresponding TLB entries, which violates s390 architecture requirements. The fix is a revert of the patch that originally enabled ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP on s390, effectively disabling HVO for that architecture (Feedly, Kernel Patch).

Impact

Exploitation of this vulnerability on affected s390 Linux kernel systems results in reproducible kernel crashes (denial of service) and potential data corruption due to improper page table manipulation without correct TLB invalidation. The impact is limited to systems running the Linux kernel on IBM s390 (mainframe) architecture with HVO enabled, and does not affect other architectures. There is no known confidentiality or remote code execution impact; the primary risks are system instability and data integrity loss (Feedly).

Mitigation and workarounds

The fix has been backported to multiple stable Linux kernel branches: version 6.6.117, 6.12.58, 6.17.8, and 6.18, as well as the mainline kernel. Administrators running Linux on s390 hardware should update to one of these patched versions. As a workaround prior to patching, disabling HugeTLB Vmemmap Optimization (ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP) in the kernel configuration will prevent the issue. Qualys scanners have detection IDs available (e.g., 6031981, 6032019, 6032592) to identify vulnerable systems (Feedly, Kernel Patch).

Community reactions

The vulnerability was reported internally by Luiz Capitulino, who identified the reproducible crashes when HVO was enabled on s390. Coverage has been limited to vulnerability tracking databases and Linux security update channels, with no significant broader media or social media discussion noted (Feedly).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management