Stable kernels still exposed to CVE-2025-37964 after bad backport
Misordered TLB fix in Linux 6.1, 6.6, and 6.12 left processes able to run with stale translations.
A backport meant to close CVE-2025-37964 left the x86 TLB race open in the Linux 6.1, 6.6, and 6.12 stable series, so the vulnerability those trees claimed to fix was still reachable.
CVE-2025-37964 covers a window during address-space switches in which a TLB flush can be skipped. A process can then keep running with stale translations, usually appearing as rare memory corruption or segfaults that are difficult to bisect. The intended cure is strict ordering: the switching CPU must advertise that a switch is in progress before it reads the TLB generation counter. A concurrent shootdown then either sends an IPI or the switching CPU observes the newer generation.
When the fix was carried into those three stable trees, the two steps were reversed. The flag write landed after the generation read, so the race the CVE patch was supposed to eliminate remained open. Mainline itself was already correct after later refactoring; the mistake was stable-specific.
Stephen Dolan supplied the corrected ordering and reported that the flawed backports still failed a focused reproducer on 6.1, 6.6, and 6.12. Separate confirmation came from workload runs: Seth Forshee saw segfaults on 6.12 within about half an hour that disappeared for an 18-hour clean run after the reorder, and Greg Thelen reported matching test failures on 6.6 and 6.12 cleared by the same change. Dave Hansen acked the stable fix.
The reordering is now headed into the affected stable kernels so the CVE is actually closed there.