5.5

CVE-2025-38489

s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again

In the Linux kernel, the following vulnerability has been resolved:

s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again

Commit 7ded842b356d ("s390/bpf: Fix bpf_plt pointer arithmetic") has
accidentally removed the critical piece of commit c730fce7c70c
("s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL"), causing
intermittent kernel panics in e.g. perf's on_switch() prog to reappear.

Restore the fix and add a comment.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.6.26 < 6.6.100
Linux ≫ Linux Kernel Version >= 6.8.5 < 6.9
Linux ≫ Linux Kernel Version >= 6.9.1 < 6.12.40
Linux ≫ Linux Kernel Version >= 6.13 < 6.15.8
Linux ≫ Linux Kernel Version 6.9 Update -
Linux ≫ Linux Kernel Version 6.9 Update rc2
Linux ≫ Linux Kernel Version 6.9 Update rc3
Linux ≫ Linux Kernel Version 6.9 Update rc4
Linux ≫ Linux Kernel Version 6.9 Update rc5
Linux ≫ Linux Kernel Version 6.9 Update rc6
Linux ≫ Linux Kernel Version 6.9 Update rc7
Linux ≫ Linux Kernel Version 6.16 Update rc1
Linux ≫ Linux Kernel Version 6.16 Update rc2
Linux ≫ Linux Kernel Version 6.16 Update rc3
Linux ≫ Linux Kernel Version 6.16 Update rc4
Linux ≫ Linux Kernel Version 6.16 Update rc5
Linux ≫ Linux Kernel Version 6.16 Update rc6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.038
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://git.kernel.org/stable/c/0c7b20f7785cfdd59403333612c90b458b12307c
Patch
https://git.kernel.org/stable/c/d5629d1af0600f8cc7c9245e8d832a66358ef889
Patch
https://git.kernel.org/stable/c/a4f9c7846b1ac428921ce9676b1b8c80ed60093c
Patch
https://git.kernel.org/stable/c/6a5abf8cf182f577c7ae6c62f14debc9754ec986
Patch