-

CVE-2025-38424

In the Linux kernel, the following vulnerability has been resolved:

perf: Fix sample vs do_exit()

Baisheng Gao reported an ARM64 crash, which Mark decoded as being a
synchronous external abort -- most likely due to trying to access
MMIO in bad ways.

The crash further shows perf trying to do a user stack sample while in
exit_mmap()'s tlb_finish_mmu() -- i.e. while tearing down the address
space it is trying to access.

It turns out that we stop perf after we tear down the userspace mm; a
receipie for disaster, since perf likes to access userspace for
various reasons.

Flip this order by moving up where we stop perf in do_exit().

Additionally, harden PERF_SAMPLE_CALLCHAIN and PERF_SAMPLE_STACK_USER
to abort when the current task does not have an mm (exit_mm() makes
sure to set current->mm = NULL; before commencing with the actual
teardown). Such that CPU wide events don't trip on this same problem.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 7b8f3c72175c6a63a95cf2e219f8b78e2baad34e
Version c5ebcedb566ef17bda7b02686e0d658a7bb42ee7
Status affected
Version < 507c9a595bad3abd107c6a8857d7fd125d89f386
Version c5ebcedb566ef17bda7b02686e0d658a7bb42ee7
Status affected
Version < a9f6aab7910a0ef2895797f15c947f6d1053160f
Version c5ebcedb566ef17bda7b02686e0d658a7bb42ee7
Status affected
Version < 975ffddfa2e19823c719459d2364fcaa17673964
Version c5ebcedb566ef17bda7b02686e0d658a7bb42ee7
Status affected
Version < 2ee6044a693735396bb47eeaba1ac3ae26c1c99b
Version c5ebcedb566ef17bda7b02686e0d658a7bb42ee7
Status affected
Version < 456019adaa2f5366b89c868dea9b483179bece54
Version c5ebcedb566ef17bda7b02686e0d658a7bb42ee7
Status affected
Version < 7311970d07c4606362081250da95f2c7901fc0db
Version c5ebcedb566ef17bda7b02686e0d658a7bb42ee7
Status affected
Version < 4f6fc782128355931527cefe3eb45338abd8ab39
Version c5ebcedb566ef17bda7b02686e0d658a7bb42ee7
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 3.7
Status affected
Version < 3.7
Version 0
Status unaffected
Version <= 5.4.*
Version 5.4.295
Status unaffected
Version <= 5.10.*
Version 5.10.239
Status unaffected
Version <= 5.15.*
Version 5.15.186
Status unaffected
Version <= 6.1.*
Version 6.1.142
Status unaffected
Version <= 6.6.*
Version 6.6.95
Status unaffected
Version <= 6.12.*
Version 6.12.35
Status unaffected
Version <= 6.15.*
Version 6.15.4
Status unaffected
Version <= *
Version 6.16
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.103
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string