5.5

CVE-2025-38528

bpf: Reject %p% format string in bprintf-like helpers

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject %p% format string in bprintf-like helpers

static const char fmt[] = "%p%";
    bpf_trace_printk(fmt, sizeof(fmt));

The above BPF program isn't rejected and causes a kernel warning at
runtime:

    Please remove unsupported %\x00 in format string
    WARNING: CPU: 1 PID: 7244 at lib/vsprintf.c:2680 format_decode+0x49c/0x5d0

This happens because bpf_bprintf_prepare skips over the second %,
detected as punctuation, while processing %p. This patch fixes it by
not skipping over punctuation. %\x00 is then processed in the next
iteration and rejected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.13 < 5.15.190
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.147
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.100
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.40
Linux ≫ Linux Kernel Version >= 6.13 < 6.15.8
Linux ≫ Linux Kernel Version 6.16 Update rc1
Linux ≫ Linux Kernel Version 6.16 Update rc2
Linux ≫ Linux Kernel Version 6.16 Update rc3
Linux ≫ Linux Kernel Version 6.16 Update rc4
Linux ≫ Linux Kernel Version 6.16 Update rc5
Linux ≫ Linux Kernel Version 6.16 Update rc6
Debian ≫ Debian Linux Version 11.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.056
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/61d5fa45ed13e42af14c7e959baba9908b8ee6d4
Patch
https://git.kernel.org/stable/c/e7be679124bae8cf4fa6e40d7e1661baddfb3289
Patch
https://git.kernel.org/stable/c/6952aeace93f8c9ea01849efecac24dd3152c9c9
Patch
https://git.kernel.org/stable/c/1c5f5fd47bbda17cb885fe6f03730702cd53d3f8
Patch
https://git.kernel.org/stable/c/f8242745871f81a3ac37f9f51853d12854fd0b58
Patch
https://git.kernel.org/stable/c/97303e541e12f1fea97834ec64b98991e8775f39
Patch
https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
Third Party Advisory
Mailing List