CVE-2025-39883 is a use-after-free flaw in the Linux kernel's memory-failure handling that can cause a kernel panic when memory is unpoisoned. An attacker with local, low-privileged access can provide an offline memory PFN through the hwpoison debugfs interface, leading unpoison_memory() to inspect the PG_HWPoison flag on an uninitialized page and trigger VM_BUG_ON_PAGE(PagePoisoned(page)). The defect has existed since Linux kernel 4.13 and affects system availability and potentially integrity.
Fixes are available in stable kernel releases 6.1.153, 6.6.107, 6.12.48, 6.16.8, and 6.17-rc6; the Linux kernel CVE team advises updating to a current stable release rather than cherry-picking patches. Red Hat rates the issue Moderate, with a CVSS 3.1 score of 7.0, and has issued fixes for multiple Red Hat Enterprise Linux 8 and 10 kernel streams; it reports no qualifying mitigation.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:22387 and RHSA-2025:22388 for RHEL 8 kernel-rt and kernel packages, respectively, and RHSA-2025:22395 for RHEL 10 kernel packages.
Red Hat released RHSA-2025:22006 with fixes for affected RHEL 8.6 kernel streams, including Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
CVE-2025-39883 was published for a use-after-free issue in mm/memory-failure.c that can trigger VM_BUG_ON_PAGE(PagePoisoned(page)) and a fatal kernel panic during memory unpoisoning. The Linux kernel CVE team identified fixed stable versions including 6.1.153, 6.6.107, 6.12.48, 6.16.8, and 6.17-rc6, and advised deploying a current stable kernel release.
CVE-2025-21786 is a resolved Linux kernel workqueue use-after-free flaw caused by prematurely releasing a pool workqueue reference while a rescuer worker is detached. Red Hat addressed the issue for RHEL 9, RHEL 9.6 Extended Update Support, and RHEL 10 through cited RHSA advisories.
Red Hat released RHSA-2026:0533 with fixed kernel packages for RHEL 8.4 Advanced Mission Critical Update Support and RHEL 8.4 Extended Update Support Long-Life Add-On.
Red Hat released RHSA-2026:0271 with fixed kernel packages for the RHEL 10.0 Extended Update Support stream.
Red Hat released RHSA-2025:23445 with fixed kernel packages for the RHEL 8.2 Advanced Update Support stream.
The vulnerable behavior was introduced in Linux kernel 4.13 by commit f1dd2cd13c4bbbc9a7c4617b3b034fa643de98fe. It allows unpoison_memory() to inspect an uninitialized page after an offline PFN is supplied through the hwpoison debugfs interface.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.