CVE-2025-40353

Source
https://cve.org/CVERecord?id=CVE-2025-40353
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40353.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40353
Downstream
Related
Published
2025-12-16T13:30:26.273Z
Modified
2026-03-12T03:54:40.025734Z
Summary
arm64: mte: Do not warn if the page is already tagged in copy_highpage()
Details

In the Linux kernel, the following vulnerability has been resolved:

arm64: mte: Do not warn if the page is already tagged in copy_highpage()

The arm64 copyhighpage() assumes that the destination page is newly allocated and not MTE-tagged (PGmtetagged unset) and warns accordingly. However, following commit 060913999d7a ("mm: migrate: support poisoned recover from migrate folio"), foliomc_copy() is called before _foliomigratemapping(). If the latter fails (-EAGAIN), the copy will be done again to the same destination page. Since copyhighpage() already set the PGmtetagged flag, this second copy will warn.

Replace the WARNONONCE(page already tagged) in the arm64 copy_highpage() with a comment.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40353.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
060913999d7a9e50c283fdb15253fc27974ddadc
Fixed
5ff5765a1fc526f07d3bbaedb061d970eb13bcf4
Fixed
0bbf3fc6e9211fce9889fe8efbb89c220504d617
Fixed
b98c94eed4a975e0c80b7e90a649a46967376f58

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40353.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.56
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40353.json"