CVE-2025-21815: Linux Kernel
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: mm/compaction: fix UBSAN shift-out-of-bounds warning syzkaller reported a UBSAN shift-out-of-bounds warning of (1UL << order) in isolate_freepages_block(). The bogus compound_order can be any value because it is union with flags. Add back the MAX_PAGE_ORDER check to fix the warning.
Affected products
- Linux Linux Kernel: from 6.7, before 6.12.14 (fixed in 6.12.14); from 6.13, before 6.13.3 (fixed in 6.13.3)
Published 2025-02-27. Last modified 2026-06-17.