In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: take vmap_purge_lock in shrinker decay_va_pool_node() can be invoked concurrently from two paths: __purge_vmap_area_lazy() when pools are being purged, and the shrinker via vmap_node_shrink_scan(). However, decay_va_pool_node() is not safe to run concurrently, and the shrinker path currently lacks serialization, leading to races and possible leaks. Protect decay_va_pool_node() by taking vmap_purge_lock in the shrinker path to ensure serialization with purge users.
Update Linux/Linux to c15ff206ba78820bf2873d0c668a882e99f4b631 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanmm/vmalloc: take vmap_purge_lock in shrinker affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: take vmap_purge_lock in shrinker decay_va_pool_node() can be invoked concurrently from two paths: __purge_vmap_area_lazy() when pools are being purged, and the shrinker via vmap_node_shrink_scan(). However, decay_va_pool_node() is not safe to run concurrently, and the shrinker path currently lacks serialization, leading to races and possible leaks. Protect decay_va_pool_node() by taking vmap_purge_lock in the shrinker path to ensure serialization with purge users.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric |
In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: take vmap_purge_lock in shrinker decay_va_pool_node() can be invoked concurrently from two paths: __purge_vmap_area_lazy() when pools are being purged, and the shrinker via vmap_node_shrink_scan(). However, decay_va_pool_node() is not safe to run concurrently, and the shrinker path currently lacks serialization, leading to races and possible leaks. Protect decay_va_pool_node() by taking vmap_purge_lock in the shrinker path to ensure serialization with purge users.
Update Linux/Linux to c15ff206ba78820bf2873d0c668a882e99f4b631 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanmm/vmalloc: take vmap_purge_lock in shrinker affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: take vmap_purge_lock in shrinker decay_va_pool_node() can be invoked concurrently from two paths: __purge_vmap_area_lazy() when pools are being purged, and the shrinker via vmap_node_shrink_scan(). However, decay_va_pool_node() is not safe to run concurrently, and the shrinker path currently lacks serialization, leading to races and possible leaks. Protect decay_va_pool_node() by taking vmap_purge_lock in the shrinker path to ensure serialization with purge users.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric |
| >=7679ba6b36dbb300b757b672d6a32a606499e14b <c15ff206ba78820bf2873d0c668a882e99f4b631 || >=7679ba6b36dbb300b757b672d6a32a606499e14b <687ccdf582169cd680aeaf24cc953807c4cd4345 || >=7679ba6b36dbb300b757b672d6a32a606499e14b <12f2341b4c235d5593a433abac201c1c6725787f || >=7679ba6b36dbb300b757b672d6a32a606499e14b <ec05f51f1e65bce95528543eb73fda56fd201d94 |
| c15ff206ba78820bf2873d0c668a882e99f4b631, 687ccdf582169cd680aeaf24cc953807c4cd4345, 12f2341b4c235d5593a433abac201c1c6725787f, ec05f51f1e65bce95528543eb73fda56fd201d94 |
| Linux/Linuxgeneric | 6.9 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=7679ba6b36dbb300b757b672d6a32a606499e14b <c15ff206ba78820bf2873d0c668a882e99f4b631 || >=7679ba6b36dbb300b757b672d6a32a606499e14b <687ccdf582169cd680aeaf24cc953807c4cd4345 || >=7679ba6b36dbb300b757b672d6a32a606499e14b <12f2341b4c235d5593a433abac201c1c6725787f || >=7679ba6b36dbb300b757b672d6a32a606499e14b <ec05f51f1e65bce95528543eb73fda56fd201d94 |
| c15ff206ba78820bf2873d0c668a882e99f4b631, 687ccdf582169cd680aeaf24cc953807c4cd4345, 12f2341b4c235d5593a433abac201c1c6725787f, ec05f51f1e65bce95528543eb73fda56fd201d94 |
| Linux/Linuxgeneric | 6.9 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard