{"id":"DEBIAN-CVE-2025-21931","details":"In the Linux kernel, the following vulnerability has been resolved:  hwpoison, memory_hotplug: lock folio before unmap hwpoisoned folio  Commit b15c87263a69 (\"hwpoison, memory_hotplug: allow hwpoisoned pages to be offlined) add page poison checks in do_migrate_range in order to make offline hwpoisoned page possible by introducing isolate_lru_page and try_to_unmap for hwpoisoned page.  However folio lock must be held before calling try_to_unmap.  Add it to fix this problem.  Warning will be produced if folio is not locked during unmap:    ------------[ cut here ]------------   kernel BUG at ./include/linux/swapops.h:400!   Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP   Modules linked in:   CPU: 4 UID: 0 PID: 411 Comm: bash Tainted: G        W          6.13.0-rc1-00016-g3c434c7ee82a-dirty #41   Tainted: [W]=WARN   Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015   pstate: 40400005 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)   pc : try_to_unmap_one+0xb08/0xd3c   lr : try_to_unmap_one+0x3dc/0xd3c   Call trace:    try_to_unmap_one+0xb08/0xd3c (P)    try_to_unmap_one+0x3dc/0xd3c (L)    rmap_walk_anon+0xdc/0x1f8    rmap_walk+0x3c/0x58    try_to_unmap+0x88/0x90    unmap_poisoned_folio+0x30/0xa8    do_migrate_range+0x4a0/0x568    offline_pages+0x5a4/0x670    memory_block_action+0x17c/0x374    memory_subsys_offline+0x3c/0x78    device_offline+0xa4/0xd0    state_store+0x8c/0xf0    dev_attr_store+0x18/0x2c    sysfs_kf_write+0x44/0x54    kernfs_fop_write_iter+0x118/0x1a8    vfs_write+0x3a8/0x4bc    ksys_write+0x6c/0xf8    __arm64_sys_write+0x1c/0x28    invoke_syscall+0x44/0x100    el0_svc_common.constprop.0+0x40/0xe0    do_el0_svc+0x1c/0x28    el0_svc+0x30/0xd0    el0t_64_sync_handler+0xc8/0xcc    el0t_64_sync+0x198/0x19c   Code: f9407be0 b5fff320 d4210000 17ffff97 (d4210000)   ---[ end trace 0000000000000000 ]---","modified":"2026-09-01T16:06:10.478550110Z","published":"2025-04-01T16:15:23.933Z","upstream":["CVE-2025-21931"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-21931"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.140-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21931.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.19-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21931.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.19-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21931.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}