U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-21740

Change History

CVE Modified by kernel.org 3/27/2025 10:15:22 AM

Action Type Old Value New Value
Changed Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: x86/mmu: Ensure NX huge page recovery thread is alive before waking

When waking a VM's NX huge page recovery thread, ensure the thread is
actually alive before trying to wake it.  Now that the thread is spawned
on-demand during KVM_RUN, a VM without a recovery thread is reachable via
the related module params.

  BUG: kernel NULL pointer dereference, address: 0000000000000040
  #PF: supervisor read access in kernel mode
  #PF: error_code(0x0000) - not-present page
  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
  RIP: 0010:vhost_task_wake+0x5/0x10
  Call Trace:
   <TASK>
   set_nx_huge_pages+0xcc/0x1e0 [kvm]
   param_attr_store+0x8a/0xd0
   module_attr_store+0x1a/0x30
   kernfs_fop_write_iter+0x12f/0x1e0
   vfs_write+0x233/0x3e0
   ksys_write+0x60/0xd0
   do_syscall_64+0x5b/0x160
   entry_SYSCALL_64_after_hwframe+0x4b/0x53
  RIP: 0033:0x7f3b52710104
   </TASK>
  Modules linked in: kvm_intel kvm
  CR2: 0000000000000040
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Removed CVSS V3.1
NIST: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

								
						
Removed CWE
NIST: CWE-476

								
						
Removed CPE Configuration
OR
          *cpe:2.3:o:linux:linux_kernel:6.14:rc1:*:*:*:*:*:*

								
						
Removed Reference
kernel.org: https://git.kernel.org/stable/c/2b3928b7c896e5a9fb6b1373924adafe8e01a0c6

								
						
Removed Reference
kernel.org: https://git.kernel.org/stable/c/43fb96ae78551d7bfa4ecca956b258f085d67c40

								
						
Removed Reference
kernel.org: https://git.kernel.org/stable/c/974f85f1f7eb7dc7fce0988046e06eeccab576a7

								
						
Removed Reference Type
kernel.org: https://git.kernel.org/stable/c/2b3928b7c896e5a9fb6b1373924adafe8e01a0c6 Types: Patch

								
						
Removed Reference Type
kernel.org: https://git.kernel.org/stable/c/43fb96ae78551d7bfa4ecca956b258f085d67c40 Types: Patch

								
						
Removed Reference Type
kernel.org: https://git.kernel.org/stable/c/974f85f1f7eb7dc7fce0988046e06eeccab576a7 Types: Patch

								
						

CVE Rejected by kernel.org 3/27/2025 10:15:22 AM

Action Type Old Value New Value