CVE-2025-21895

MEDIUM EPSS 2.6%
Published Apr 1, 20251y ago · Modified Jun 17, 20261w ago
4.7 CVSS 3.1
Medium
Find Similar
Published Apr 1, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: perf/core: Order the PMU list to fix warning about unordered pmu_ctx_list Syskaller triggers a warning due to prev_epc->pmu != next_epc->pmu in perf_event_swap_task_ctx_data(). vmcore shows that two lists have the same perf_event_pmu_context, but not in the same order. The problem is that the order of pmu_ctx_list for the parent is impacted by the time when an event/PMU is added. While the order for a child is impacted by the event order in the pinned_groups and flexible_groups. So the order of pmu_ctx_list in the parent and child may be different. To fix this problem, insert the perf_event_pmu_context to its proper place after iteration of the pmu_ctx_list. The follow testcase can trigger above warning: # perf record -e cycles --call-graph lbr -- taskset -c 3 ./a.out & # perf stat -e cpu-clock,cs -p xxx // xxx is the pid of a.out test.c void main() { int count = 0; pid_t pid; printf("%d running\n", getpid()); sleep(30); printf("running\n"); pid = fork(); if (pid == -1) { printf("fork error\n"); return; } if (pid == 0) { while (1) { count++; } } else { while (1) { count++; } } } The testcase first opens an LBR event, so it will allocate task_ctx_data, and then open tracepoint and software events, so the parent context will have 3 different perf_event_pmu_contexts. On inheritance, child ctx will insert the perf_event_pmu_context in another order and the warning will trigger. [ mingo: Tidied up the changelog. ]

CVSS Details

Base Score
4.7
Exploitability
1.0
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-362

Affected Products 7

VendorProductVersionRange
linuxlinux_kernel*≥6.2  –  <6.6.81
linuxlinux_kernel*≥6.7  –  <6.12.18
linuxlinux_kernel*≥6.13  –  <6.13.6
linuxlinux_kernel6.14any
linuxlinux_kernel6.14any
linuxlinux_kernel6.14any
linuxlinux_kernel6.14any

References 4

  • git.kernel.org https://git.kernel.org/stable/c/2016066c66192a99d9e0ebf433789c490a6785a2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3e812a70732d84b7873cea61a7f6349b9a9dcbf5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7d582eb6e4e100959ba07083d7563453c8c2a343
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f0c3971405cef6892844016aa710121a02da3a23
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/2016066c66192a99d9e0ebf433789c490a6785a2
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3e812a70732d84b7873cea61a7f6349b9a9dcbf5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7d582eb6e4e100959ba07083d7563453c8c2a343
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f0c3971405cef6892844016aa710121a02da3a23
    Patch