Answer in brief
CVE-2025-40272 records a Unknown severity vulnerability in mm/secretmem: fix use-after-free race in fault handler. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <bb1c19636aedae39360e6fdbcaef4f2bcff25785 || >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <1e4643d6628edf9c0047b1f8f5bc574665025acb || >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <42d486d35a4143cc37fc72ee66edc99d942dd367 || >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <52f2d5cf33de9a8f5e72bbb0ed38282ae0bc4649 || >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <4444767e625da46009fc94a453fd1967b80ba047 || >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <6f86d0534fddfbd08687fa0f01479d4226bc3c3d | bb1c19636aedae39360e6fdbcaef4f2bcff25785, 1e4643d6628edf9c0047b1f8f5bc574665025acb, 42d486d35a4143cc37fc72ee66edc99d942dd367, 52f2d5cf33de9a8f5e72bbb0ed38282ae0bc4649, 4444767e625da46009fc94a453fd1967b80ba047, 6f86d0534fddfbd08687fa0f01479d4226bc3c3d |
| Linux/Linuxgeneric | 5.14 | Not reported |
Published upstream
Dec 6, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: mm/secretmem: fix use-after-free race in fault handler When a page fault occurs in a secret memory file created with `memfd_secret(2)`, the kernel will allocate a new folio for it, mark the underlying page as not-present in the direct map, and add it to the file mapping. If two tasks cause a fault in the same page concurrently, both could end up allocating a folio and removing the page from the direct map, but only one would succeed in adding the folio to the file mapping. The task that failed undoes the effects of its attempt by (a) freeing the folio again and (b) putting the page back into the direct map. However, by doing these two operations in this order, the page becomes available to the allocator again before it is placed back in the direct mapping. If another task attempts to allocate the page between (a) and (b), and the kernel tries to access it via the direct map, it would result in a supervisor not-present page fault. Fix the ordering to restore the direct map before the folio is freed.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-40272 records a Unknown severity vulnerability in mm/secretmem: fix use-after-free race in fault handler. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <bb1c19636aedae39360e6fdbcaef4f2bcff25785 || >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <1e4643d6628edf9c0047b1f8f5bc574665025acb || >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <42d486d35a4143cc37fc72ee66edc99d942dd367 || >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <52f2d5cf33de9a8f5e72bbb0ed38282ae0bc4649 || >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <4444767e625da46009fc94a453fd1967b80ba047 || >=1507f51255c9ff07d75909a84e7c0d7f3c4b2f49 <6f86d0534fddfbd08687fa0f01479d4226bc3c3d | bb1c19636aedae39360e6fdbcaef4f2bcff25785, 1e4643d6628edf9c0047b1f8f5bc574665025acb, 42d486d35a4143cc37fc72ee66edc99d942dd367, 52f2d5cf33de9a8f5e72bbb0ed38282ae0bc4649, 4444767e625da46009fc94a453fd1967b80ba047, 6f86d0534fddfbd08687fa0f01479d4226bc3c3d |
| Linux/Linuxgeneric | 5.14 | Not reported |
Published upstream
Dec 6, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: mm/secretmem: fix use-after-free race in fault handler When a page fault occurs in a secret memory file created with `memfd_secret(2)`, the kernel will allocate a new folio for it, mark the underlying page as not-present in the direct map, and add it to the file mapping. If two tasks cause a fault in the same page concurrently, both could end up allocating a folio and removing the page from the direct map, but only one would succeed in adding the folio to the file mapping. The task that failed undoes the effects of its attempt by (a) freeing the folio again and (b) putting the page back into the direct map. However, by doing these two operations in this order, the page becomes available to the allocator again before it is placed back in the direct mapping. If another task attempts to allocate the page between (a) and (b), and the kernel tries to access it via the direct map, it would result in a supervisor not-present page fault. Fix the ordering to restore the direct map before the folio is freed.
Quoted source text, attributed separately from HOL analysis.