-

CVE-2025-40358

riscv: stacktrace: Disable KASAN checks for non-current tasks

In the Linux kernel, the following vulnerability has been resolved:

riscv: stacktrace: Disable KASAN checks for non-current tasks

Unwinding the stack of a task other than current, KASAN would report
"BUG: KASAN: out-of-bounds in walk_stackframe+0x41c/0x460"

There is a same issue on x86 and has been resolved by the commit
84936118bdf3 ("x86/unwind: Disable KASAN checks for non-current tasks")
The solution could be applied to RISC-V too.

This patch also can solve the issue:
https://seclists.org/oss-sec/2025/q4/23

[pjw@kernel.org: clean up checkpatch issues]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 5d8544e2d0075a5f3c9a2cf27152354d54360da1
Version < ef4d626ac59a56f8ec5cc09c1fef26f2923eec6f
Status affected
Version 5d8544e2d0075a5f3c9a2cf27152354d54360da1
Version < f34ba22989da61186f30a40b6a82e0b3337b96fc
Status affected
Version 5d8544e2d0075a5f3c9a2cf27152354d54360da1
Version < 27379fcc15a10d3e3780fe79ba3fc7ed1ccd78e2
Status affected
Version 5d8544e2d0075a5f3c9a2cf27152354d54360da1
Version < 2c8d2b53866fb229b438296526ef0fa5a990e5e5
Status affected
Version 5d8544e2d0075a5f3c9a2cf27152354d54360da1
Version < 060ea84a484e852b52b938f234bf9b5503a6c910
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.15
Status affected
Version 0
Version < 4.15
Status unaffected
Version <= 6.1.*
Version 6.1.167
Status unaffected
Version <= 6.6.*
Version 6.6.117
Status unaffected
Version <= 6.12.*
Version 6.12.58
Status unaffected
Version <= 6.17.*
Version 6.17.8
Status unaffected
Version <= *
Version 6.18
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.