-

CVE-2025-40319

bpf: Sync pending IRQ work before freeing ring buffer

In the Linux kernel, the following vulnerability has been resolved:

bpf: Sync pending IRQ work before freeing ring buffer

Fix a race where irq_work can be queued in bpf_ringbuf_commit()
but the ring buffer is freed before the work executes.
In the syzbot reproducer, a BPF program attached to sched_switch
triggers bpf_ringbuf_commit(), queuing an irq_work. If the ring buffer
is freed before this work executes, the irq_work thread may accesses
freed memory.
Calling `irq_work_sync(&rb->work)` ensures that all pending irq_work
complete before freeing the buffer.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 457f44363a8894135c85b7a9afd2bd8196db24ab
Version < 47626748a2a00068dbbd5836d19076637b4e235b
Status affected
Version 457f44363a8894135c85b7a9afd2bd8196db24ab
Version < de2ce6b14bc3e565708a39bdba3ef9162aeffc72
Status affected
Version 457f44363a8894135c85b7a9afd2bd8196db24ab
Version < e1828c7a8d8135e21ff6adaaa9458c32aae13b11
Status affected
Version 457f44363a8894135c85b7a9afd2bd8196db24ab
Version < 6451141103547f4efd774e912418a3b4318046c6
Status affected
Version 457f44363a8894135c85b7a9afd2bd8196db24ab
Version < 10ca3b2eec384628bc9f5d8190aed9427ad2dde6
Status affected
Version 457f44363a8894135c85b7a9afd2bd8196db24ab
Version < 430e15544f11f8de26b2b5109c7152f71b78295e
Status affected
Version 457f44363a8894135c85b7a9afd2bd8196db24ab
Version < 4e9077638301816a7d73fa1e1b4c1db4a7e3b59c
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.8
Status affected
Version 0
Version < 5.8
Status unaffected
Version <= 5.10.*
Version 5.10.247
Status unaffected
Version <= 5.15.*
Version 5.15.197
Status unaffected
Version <= 6.1.*
Version 6.1.159
Status unaffected
Version <= 6.6.*
Version 6.6.117
Status unaffected
Version <= 6.12.*
Version 6.12.58
Status unaffected
Version <= 6.17.*
Version 6.17.8
Status unaffected
Version <= *
Version 6.18
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.129
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.