Impact
The flaw occurs in the Linux kernel’s mm/migrate_device component, where functions migrate_device_range() and migrate_device_pfns() clear entries for compound folios without enforcing bounds on the PFN array. If a compound folio extends beyond the caller‑supplied range, the loops write outside the allocated array, causing an out-of-bounds memory corruption. This corruption affects kernel memory integrity, which could compromise system stability and security. The kernel documentation does not explicitly state that the resulting corruption could enable privilege escalation; however, as kernel memory corruption is a typical precondition for privilege escalation, this possibility is inferred from the nature of the bug.
Affected Systems
Linux kernel versions containing the unpatched migrate_device code are at risk. The CVE lists Linux:Linux in the product table, indicating all Linux kernel releases are potentially affected until the patch is applied. The vulnerability was observed in a KASAN‑instrumented x86 QEMU kernel during a heavy device memory migration self‑test that exercised /dev/hmm_dmirror0.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity, and the EPSS score of less than 1% indicates a low probability of widespread exploitation at this time. The vulnerability is not catalogued in the CISA KEV list. The attack vector is inferred to involve triggering a device memory migration through interfaces such as /dev/hmm_dmirror0; the exact method an attacker would need to use is not detailed in the description, so this inference is explicitly noted. Monitoring for signs of malicious migration activity and restricting device access can mitigate the risk until a corrective kernel update is applied.
OpenCVE Enrichment