CVE-2025-38424

MEDIUM EPSS 6.7%
Published Jul 25, 202511mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jul 25, 2025 11mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: perf: Fix sample vs do_exit() Baisheng Gao reported an ARM64 crash, which Mark decoded as being a synchronous external abort -- most likely due to trying to access MMIO in bad ways. The crash further shows perf trying to do a user stack sample while in exit_mmap()'s tlb_finish_mmu() -- i.e. while tearing down the address space it is trying to access. It turns out that we stop perf after we tear down the userspace mm; a receipie for disaster, since perf likes to access userspace for various reasons. Flip this order by moving up where we stop perf in do_exit(). Additionally, harden PERF_SAMPLE_CALLCHAIN and PERF_SAMPLE_STACK_USER to abort when the current task does not have an mm (exit_mm() makes sure to set current->mm = NULL; before commencing with the actual teardown). Such that CPU wide events don't trip on this same problem.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
6.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 10

VendorProductVersionRange
linuxlinux_kernel*≥3.7  –  <5.4.295
linuxlinux_kernel*≥5.5  –  <5.10.239
linuxlinux_kernel*≥5.11  –  <5.15.186
linuxlinux_kernel*≥5.16  –  <6.1.142
linuxlinux_kernel*≥6.2  –  <6.6.95
linuxlinux_kernel*≥6.7  –  <6.12.35
linuxlinux_kernel*≥6.13  –  <6.15.4
linuxlinux_kernel6.16any
linuxlinux_kernel6.16any
debiandebian_linux11.0any

References 10

  • git.kernel.org https://git.kernel.org/stable/c/2ee6044a693735396bb47eeaba1ac3ae26c1c99b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/456019adaa2f5366b89c868dea9b483179bece54
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4f6fc782128355931527cefe3eb45338abd8ab39
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/507c9a595bad3abd107c6a8857d7fd125d89f386
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7311970d07c4606362081250da95f2c7901fc0db
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7b8f3c72175c6a63a95cf2e219f8b78e2baad34e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/975ffddfa2e19823c719459d2364fcaa17673964
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a9f6aab7910a0ef2895797f15c947f6d1053160f
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
    Mailing ListThird Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Mailing ListThird Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/2ee6044a693735396bb47eeaba1ac3ae26c1c99b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/456019adaa2f5366b89c868dea9b483179bece54
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4f6fc782128355931527cefe3eb45338abd8ab39
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/507c9a595bad3abd107c6a8857d7fd125d89f386
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7311970d07c4606362081250da95f2c7901fc0db
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7b8f3c72175c6a63a95cf2e219f8b78e2baad34e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/975ffddfa2e19823c719459d2364fcaa17673964
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a9f6aab7910a0ef2895797f15c947f6d1053160f
    Patch