CVE-2025-39883 affects the Linux kernel memory-failure subsystem. The unpoison_memory() function attempts to inspect PG_HWPoison flags on an uninitialized page when given a page frame number belonging to offline memory. This triggers VM_BUG_ON_PAGE(PagePoisoned(page)), causing a kernel BUG and fatal kernel panic. The issue was introduced in Linux 4.13. The fix rejects the unpoisoning operation when pfn_to_online_page() returns NULL, preventing inspection of the invalid page. Although classified as a use-after-free vulnerability, the documented failure mechanism is an invalid flag check on an uninitialized offline page.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel memory-failure handling vulnerability can trigger a kernel panic when unpoison_memory() checks an uninitialized page associated with offlined memory. The content provides reproduction steps and describes a fix that rejects pages when pfn_to_online_page() returns NULL. The advisory assigns a CVSS v3 base score of 7.1 and recommends updating the affected Google COS kernel packages to version 18613.339.77 or later.
A high-severity local Linux kernel denial-of-service vulnerability in memory-failure handling. A locally privileged user able to access the relevant hwpoison debugfs interface can reproduce a kernel panic by writing an offline-memory PFN to unpoison-pfn. Google COS packages sys-kernel/csql-kernel-6_1 and sys-kernel/lakitu-kernel-6_1 are affected; version 18244.448.58 or later fixes the issue.
A Linux kernel memory-failure handling flaw that can cause a local kernel panic/denial of service when unpoisoning an offline memory page. The fix rejects PFNs for which pfn_to_online_page() returns NULL.
A Linux kernel memory-failure handling flaw triggered while unpoisoning memory.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.