In the Linux kernel, the following vulnerability has been resolved: mm/zone_device: do not touch device folio after calling ->folio_free() The contents of a device folio can immediately change after calling ->folio_free(), as the folio may be reallocated by a driver with a different order. Instead of touching the folio again to extract the pgmap, use the local stack variable when calling percpu_ref_put_many().
Update Linux/Linux to 85be0a262e39c706edb53c88af8afde2e98222ba if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanmm/zone_device: do not touch device folio after calling ->folio_free() affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: mm/zone_device: do not touch device folio after calling ->folio_free() The contents of a device folio can immediately change after calling ->folio_free(), as the folio may be reallocated by a driver with a different order. Instead of touching the folio again to extract the pgmap, use the local stack variable when calling percpu_ref_put_many().
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d245f9b4ab806733a77e51a218ca7b8bc3135cd9 <85be0a262e39c706edb53c88af8afde2e98222ba || >=d245f9b4ab806733a77e51a218ca7b8bc3135cd9 <39928984956037cabd304321cb8f342e47421db5 |
In the Linux kernel, the following vulnerability has been resolved: mm/zone_device: do not touch device folio after calling ->folio_free() The contents of a device folio can immediately change after calling ->folio_free(), as the folio may be reallocated by a driver with a different order. Instead of touching the folio again to extract the pgmap, use the local stack variable when calling percpu_ref_put_many().
Update Linux/Linux to 85be0a262e39c706edb53c88af8afde2e98222ba if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanmm/zone_device: do not touch device folio after calling ->folio_free() affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: mm/zone_device: do not touch device folio after calling ->folio_free() The contents of a device folio can immediately change after calling ->folio_free(), as the folio may be reallocated by a driver with a different order. Instead of touching the folio again to extract the pgmap, use the local stack variable when calling percpu_ref_put_many().
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d245f9b4ab806733a77e51a218ca7b8bc3135cd9 <85be0a262e39c706edb53c88af8afde2e98222ba || >=d245f9b4ab806733a77e51a218ca7b8bc3135cd9 <39928984956037cabd304321cb8f342e47421db5 |
| 85be0a262e39c706edb53c88af8afde2e98222ba, 39928984956037cabd304321cb8f342e47421db5 |
| Linux/Linuxgeneric | 6.19 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 85be0a262e39c706edb53c88af8afde2e98222ba, 39928984956037cabd304321cb8f342e47421db5 |
| Linux/Linuxgeneric | 6.19 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard