CVE-2025-22035 (GCVE-0-2025-22035)
Vulnerability from cvelistv5
Published
2025-04-16 14:11
Modified
2026-08-05 11:56
Summary
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in print_graph_function_flags during tracer switching Kairui reported a UAF issue in print_graph_function_flags() during ftrace stress testing [1]. This issue can be reproduced if puting a 'mdelay(10)' after 'mutex_unlock(&trace_types_lock)' in s_start(), and executing the following script: $ echo function_graph > current_tracer $ cat trace > /dev/null & $ sleep 5 # Ensure the 'cat' reaches the 'mdelay(10)' point $ echo timerlat > current_tracer The root cause lies in the two calls to print_graph_function_flags within print_trace_line during each s_show(): * One through 'iter->trace->print_line()'; * Another through 'event->funcs->trace()', which is hidden in print_trace_fmt() before print_trace_line returns. Tracer switching only updates the former, while the latter continues to use the print_line function of the old tracer, which in the script above is print_graph_function_flags. Moreover, when switching from the 'function_graph' tracer to the 'timerlat' tracer, s_start only calls graph_trace_close of the 'function_graph' tracer to free 'iter->private', but does not set it to NULL. This provides an opportunity for 'event->funcs->trace()' to use an invalid 'iter->private'. To fix this issue, set 'iter->private' to NULL immediately after freeing it in graph_trace_close(), ensuring that an invalid pointer is not passed to other tracers. Additionally, clean up the unnecessary 'iter->private = NULL' during each 'cat trace' when using wakeup and irqsoff tracers. [1] https://lore.kernel.org/all/20231112150030.84609-1-ryncsn@gmail.com/
Impacted products
Vendor Product Version
Linux Linux Version: 05319d707732c728eb721ac616a50e7978eb499a
Version: b8205dfed68183dc1470e83863c5ded6d7fa30a9
Version: ce6e2b14bc094866d9173db6935da2d752f06d8b
Version: 2cb0c037c927db4ec928cc927488e52aa359786e
Version: eecb91b9f98d6427d4af5fdb8f108f52572a39e7
Version: eecb91b9f98d6427d4af5fdb8f108f52572a39e7
Version: eecb91b9f98d6427d4af5fdb8f108f52572a39e7
Version: eecb91b9f98d6427d4af5fdb8f108f52572a39e7
Version: eecb91b9f98d6427d4af5fdb8f108f52572a39e7
Version: d6b35c9a8d51032ed9890431da3ae39fe76c1ae3
Version: 5d433eda76b66ab271f5924b26ddfec063eeb454
Version: 2242640e9bd94e706acf75c60a2ab1d0e150e0fb
Version: 5.4.255   
Version: 5.10.193   
Version: 5.15.129   
Version: 6.1.50   
Version: 4.14.324   
Version: 4.19.293   
Version: 6.4.13   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 7.8,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2025-22035",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-04-21T14:57:52.767300Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-416",
                "description": "CWE-416 Use After Free",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-04-21T15:01:46.658Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T19:41:18.919Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "kernel/trace/trace_functions_graph.c",
            "kernel/trace/trace_irqsoff.c",
            "kernel/trace/trace_sched_wakeup.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "42561fe62c3628ea3bc9623f64f047605e98857f",
              "status": "affected",
              "version": "05319d707732c728eb721ac616a50e7978eb499a",
              "versionType": "git"
            },
            {
              "lessThan": "de7b309139f862a44379ecd96e93c9133c69f813",
              "status": "affected",
              "version": "b8205dfed68183dc1470e83863c5ded6d7fa30a9",
              "versionType": "git"
            },
            {
              "lessThan": "81a85b12132c8ffe98f5ddbdc185481790aeaa1b",
              "status": "affected",
              "version": "ce6e2b14bc094866d9173db6935da2d752f06d8b",
              "versionType": "git"
            },
            {
              "lessThan": "a2cce54c1748216535dda02e185d07a084be837e",
              "status": "affected",
              "version": "2cb0c037c927db4ec928cc927488e52aa359786e",
              "versionType": "git"
            },
            {
              "lessThan": "099ef3385800828b74933a96c117574637c3fb3a",
              "status": "affected",
              "version": "eecb91b9f98d6427d4af5fdb8f108f52572a39e7",
              "versionType": "git"
            },
            {
              "lessThan": "c85efe6e13743cac6ba4ccf144cb91f44c86231a",
              "status": "affected",
              "version": "eecb91b9f98d6427d4af5fdb8f108f52572a39e7",
              "versionType": "git"
            },
            {
              "lessThan": "f14752d66056d0c7bffe5092130409417d3baa70",
              "status": "affected",
              "version": "eecb91b9f98d6427d4af5fdb8f108f52572a39e7",
              "versionType": "git"
            },
            {
              "lessThan": "70be951bc01e4a0e10d443f3510bb17426f257fb",
              "status": "affected",
              "version": "eecb91b9f98d6427d4af5fdb8f108f52572a39e7",
              "versionType": "git"
            },
            {
              "lessThan": "7f81f27b1093e4895e87b74143c59c055c3b1906",
              "status": "affected",
              "version": "eecb91b9f98d6427d4af5fdb8f108f52572a39e7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d6b35c9a8d51032ed9890431da3ae39fe76c1ae3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5d433eda76b66ab271f5924b26ddfec063eeb454",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2242640e9bd94e706acf75c60a2ab1d0e150e0fb",
              "versionType": "git"
            },
            {
              "lessThan": "5.4.292",
              "status": "affected",
              "version": "5.4.255",
              "versionType": "semver"
            },
            {
              "lessThan": "5.10.236",
              "status": "affected",
              "version": "5.10.193",
              "versionType": "semver"
            },
            {
              "lessThan": "5.15.180",
              "status": "affected",
              "version": "5.15.129",
              "versionType": "semver"
            },
            {
              "lessThan": "6.1.134",
              "status": "affected",
              "version": "6.1.50",
              "versionType": "semver"
            },
            {
              "lessThan": "4.15",
              "status": "affected",
              "version": "4.14.324",
              "versionType": "semver"
            },
            {
              "lessThan": "4.20",
              "status": "affected",
              "version": "4.19.293",
              "versionType": "semver"
            },
            {
              "lessThan": "6.5",
              "status": "affected",
              "version": "6.4.13",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "kernel/trace/trace_functions_graph.c",
            "kernel/trace/trace_irqsoff.c",
            "kernel/trace/trace_sched_wakeup.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "lessThan": "6.5",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.292",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.236",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.180",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.134",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.87",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.23",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.13.*",
              "status": "unaffected",
              "version": "6.13.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.14.*",
              "status": "unaffected",
              "version": "6.14.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.15",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.292",
                  "versionStartIncluding": "5.4.255",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.236",
                  "versionStartIncluding": "5.10.193",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.180",
                  "versionStartIncluding": "5.15.129",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.134",
                  "versionStartIncluding": "6.1.50",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.87",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.23",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13.11",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14.2",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.15",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.14.324",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.19.293",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.4.13",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix use-after-free in print_graph_function_flags during tracer switching\n\nKairui reported a UAF issue in print_graph_function_flags() during\nftrace stress testing [1]. This issue can be reproduced if puting a\n\u0027mdelay(10)\u0027 after \u0027mutex_unlock(\u0026trace_types_lock)\u0027 in s_start(),\nand executing the following script:\n\n  $ echo function_graph \u003e current_tracer\n  $ cat trace \u003e /dev/null \u0026\n  $ sleep 5  # Ensure the \u0027cat\u0027 reaches the \u0027mdelay(10)\u0027 point\n  $ echo timerlat \u003e current_tracer\n\nThe root cause lies in the two calls to print_graph_function_flags\nwithin print_trace_line during each s_show():\n\n  * One through \u0027iter-\u003etrace-\u003eprint_line()\u0027;\n  * Another through \u0027event-\u003efuncs-\u003etrace()\u0027, which is hidden in\n    print_trace_fmt() before print_trace_line returns.\n\nTracer switching only updates the former, while the latter continues\nto use the print_line function of the old tracer, which in the script\nabove is print_graph_function_flags.\n\nMoreover, when switching from the \u0027function_graph\u0027 tracer to the\n\u0027timerlat\u0027 tracer, s_start only calls graph_trace_close of the\n\u0027function_graph\u0027 tracer to free \u0027iter-\u003eprivate\u0027, but does not set\nit to NULL. This provides an opportunity for \u0027event-\u003efuncs-\u003etrace()\u0027\nto use an invalid \u0027iter-\u003eprivate\u0027.\n\nTo fix this issue, set \u0027iter-\u003eprivate\u0027 to NULL immediately after\nfreeing it in graph_trace_close(), ensuring that an invalid pointer\nis not passed to other tracers. Additionally, clean up the unnecessary\n\u0027iter-\u003eprivate = NULL\u0027 during each \u0027cat trace\u0027 when using wakeup and\nirqsoff tracers.\n\n [1] https://lore.kernel.org/all/20231112150030.84609-1-ryncsn@gmail.com/"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reached only through local file operations on tracefs \u2014 reading `/sys/kernel/tracing/trace` while writing `current_tracer`. There is no network, adjacent-network, or physical path into `print_graph_function_flags()`.\nAC:L - The attacker owns both sides of the sequence \u2014 its own paced reader (small `read()` buffers, or SIGSTOP) and its own `current_tracer` write \u2014 so the free in `s_start()` and the use in `s_show()` can be ordered deterministically without winning any race. Once freed, `iter-\u003eprivate` stays dangling for the rest of the iterator\u0027s life, giving unlimited time to groom the ~128-byte slab.\nPR:L - `tracing_check_open_get_tr()` enforces no capability check at all \u2014 only kernel lockdown, which is off by default \u2014 so reachability is governed purely by tracefs permissions, and tracefs\u0027s `gid=` mount option is widely used (Android, ChromeOS, CI/perf and developer systems, containers with tracefs bind-mounted) to grant an unprivileged tracing group read/write on `trace` and `current_tracer`.\nUI:N - The attacker performs both the file read and the tracer switch itself; no victim action or pre-existing session state is needed.\nS:U - The freed object and all corrupted memory belong to the kernel itself, and exploitation yields kernel privileges within the same security authority \u2014 no VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is a use-after-free on a general-purpose kmalloc object, so a heap spray gives the attacker control of `data-\u003ecpu_data`, and `per_cpu_ptr(data-\u003ecpu_data, cpu)-\u003eignore` then reads arbitrary kernel memory; the `data-\u003efailed` path additionally formats attacker-supplied `data-\u003eent.ent` function addresses through `print_graph_entry()` straight into the trace output the attacker reads back.\nI:H - `per_cpu_ptr(data-\u003ecpu_data, cpu)-\u003eignore = 0` and `= 1` are writes through a pointer taken from freed, sprayable memory, yielding an arbitrary-address write primitive, and the attacker-controlled `data-\u003ecpu` is used as an unchecked per-CPU index \u2014 a classic UAF path to privilege escalation.\nA:H - Dereferencing the freed `fgraph_data` and its stale percpu pointer oopses or panics the kernel even without successful grooming, and the read can be repeated at will to crash the machine reliably."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:56:07.902Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/42561fe62c3628ea3bc9623f64f047605e98857f"
        },
        {
          "url": "https://git.kernel.org/stable/c/de7b309139f862a44379ecd96e93c9133c69f813"
        },
        {
          "url": "https://git.kernel.org/stable/c/81a85b12132c8ffe98f5ddbdc185481790aeaa1b"
        },
        {
          "url": "https://git.kernel.org/stable/c/a2cce54c1748216535dda02e185d07a084be837e"
        },
        {
          "url": "https://git.kernel.org/stable/c/099ef3385800828b74933a96c117574637c3fb3a"
        },
        {
          "url": "https://git.kernel.org/stable/c/c85efe6e13743cac6ba4ccf144cb91f44c86231a"
        },
        {
          "url": "https://git.kernel.org/stable/c/f14752d66056d0c7bffe5092130409417d3baa70"
        },
        {
          "url": "https://git.kernel.org/stable/c/70be951bc01e4a0e10d443f3510bb17426f257fb"
        },
        {
          "url": "https://git.kernel.org/stable/c/7f81f27b1093e4895e87b74143c59c055c3b1906"
        }
      ],
      "title": "tracing: Fix use-after-free in print_graph_function_flags during tracer switching",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-22035",
    "datePublished": "2025-04-16T14:11:53.958Z",
    "dateReserved": "2024-12-29T08:45:45.809Z",
    "dateUpdated": "2026-08-05T11:56:07.902Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html\"}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T19:41:18.919Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 7.8, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"HIGH\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-22035\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-04-21T14:57:52.767300Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-416\", \"description\": \"CWE-416 Use After Free\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-04-21T14:57:27.164Z\"}}], \"cna\": {\"title\": \"tracing: Fix use-after-free in print_graph_function_flags during tracer switching\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerability is reached only through local file operations on tracefs \\u2014 reading `/sys/kernel/tracing/trace` while writing `current_tracer`. There is no network, adjacent-network, or physical path into `print_graph_function_flags()`.\\nAC:L - The attacker owns both sides of the sequence \\u2014 its own paced reader (small `read()` buffers, or SIGSTOP) and its own `current_tracer` write \\u2014 so the free in `s_start()` and the use in `s_show()` can be ordered deterministically without winning any race. Once freed, `iter-\u003eprivate` stays dangling for the rest of the iterator\u0027s life, giving unlimited time to groom the ~128-byte slab.\\nPR:L - `tracing_check_open_get_tr()` enforces no capability check at all \\u2014 only kernel lockdown, which is off by default \\u2014 so reachability is governed purely by tracefs permissions, and tracefs\u0027s `gid=` mount option is widely used (Android, ChromeOS, CI/perf and developer systems, containers with tracefs bind-mounted) to grant an unprivileged tracing group read/write on `trace` and `current_tracer`.\\nUI:N - The attacker performs both the file read and the tracer switch itself; no victim action or pre-existing session state is needed.\\nS:U - The freed object and all corrupted memory belong to the kernel itself, and exploitation yields kernel privileges within the same security authority \\u2014 no VM, IOMMU, or sandbox boundary is crossed.\\nC:H - This is a use-after-free on a general-purpose kmalloc object, so a heap spray gives the attacker control of `data-\u003ecpu_data`, and `per_cpu_ptr(data-\u003ecpu_data, cpu)-\u003eignore` then reads arbitrary kernel memory; the `data-\u003efailed` path additionally formats attacker-supplied `data-\u003eent.ent` function addresses through `print_graph_entry()` straight into the trace output the attacker reads back.\\nI:H - `per_cpu_ptr(data-\u003ecpu_data, cpu)-\u003eignore = 0` and `= 1` are writes through a pointer taken from freed, sprayable memory, yielding an arbitrary-address write primitive, and the attacker-controlled `data-\u003ecpu` is used as an unchecked per-CPU index \\u2014 a classic UAF path to privilege escalation.\\nA:H - Dereferencing the freed `fgraph_data` and its stale percpu pointer oopses or panics the kernel even without successful grooming, and the read can be repeated at will to crash the machine reliably.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"05319d707732c728eb721ac616a50e7978eb499a\", \"lessThan\": \"42561fe62c3628ea3bc9623f64f047605e98857f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"b8205dfed68183dc1470e83863c5ded6d7fa30a9\", \"lessThan\": \"de7b309139f862a44379ecd96e93c9133c69f813\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"ce6e2b14bc094866d9173db6935da2d752f06d8b\", \"lessThan\": \"81a85b12132c8ffe98f5ddbdc185481790aeaa1b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2cb0c037c927db4ec928cc927488e52aa359786e\", \"lessThan\": \"a2cce54c1748216535dda02e185d07a084be837e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"eecb91b9f98d6427d4af5fdb8f108f52572a39e7\", \"lessThan\": \"099ef3385800828b74933a96c117574637c3fb3a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"eecb91b9f98d6427d4af5fdb8f108f52572a39e7\", \"lessThan\": \"c85efe6e13743cac6ba4ccf144cb91f44c86231a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"eecb91b9f98d6427d4af5fdb8f108f52572a39e7\", \"lessThan\": \"f14752d66056d0c7bffe5092130409417d3baa70\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"eecb91b9f98d6427d4af5fdb8f108f52572a39e7\", \"lessThan\": \"70be951bc01e4a0e10d443f3510bb17426f257fb\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"eecb91b9f98d6427d4af5fdb8f108f52572a39e7\", \"lessThan\": \"7f81f27b1093e4895e87b74143c59c055c3b1906\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d6b35c9a8d51032ed9890431da3ae39fe76c1ae3\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5d433eda76b66ab271f5924b26ddfec063eeb454\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2242640e9bd94e706acf75c60a2ab1d0e150e0fb\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"5.4.255\", \"lessThan\": \"5.4.292\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.10.193\", \"lessThan\": \"5.10.236\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.15.129\", \"lessThan\": \"5.15.180\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"6.1.50\", \"lessThan\": \"6.1.134\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"4.14.324\", \"lessThan\": \"4.15\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"4.19.293\", \"lessThan\": \"4.20\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"6.4.13\", \"lessThan\": \"6.5\", \"versionType\": \"semver\"}], \"programFiles\": [\"kernel/trace/trace_functions_graph.c\", \"kernel/trace/trace_irqsoff.c\", \"kernel/trace/trace_sched_wakeup.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.5\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.5\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.4.292\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.236\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.180\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.134\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.87\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12.23\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.12.*\"}, {\"status\": \"unaffected\", \"version\": \"6.13.11\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.13.*\"}, {\"status\": \"unaffected\", \"version\": \"6.14.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.14.*\"}, {\"status\": \"unaffected\", \"version\": \"6.15\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"kernel/trace/trace_functions_graph.c\", \"kernel/trace/trace_irqsoff.c\", \"kernel/trace/trace_sched_wakeup.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/42561fe62c3628ea3bc9623f64f047605e98857f\"}, {\"url\": \"https://git.kernel.org/stable/c/de7b309139f862a44379ecd96e93c9133c69f813\"}, {\"url\": \"https://git.kernel.org/stable/c/81a85b12132c8ffe98f5ddbdc185481790aeaa1b\"}, {\"url\": \"https://git.kernel.org/stable/c/a2cce54c1748216535dda02e185d07a084be837e\"}, {\"url\": \"https://git.kernel.org/stable/c/099ef3385800828b74933a96c117574637c3fb3a\"}, {\"url\": \"https://git.kernel.org/stable/c/c85efe6e13743cac6ba4ccf144cb91f44c86231a\"}, {\"url\": \"https://git.kernel.org/stable/c/f14752d66056d0c7bffe5092130409417d3baa70\"}, {\"url\": \"https://git.kernel.org/stable/c/70be951bc01e4a0e10d443f3510bb17426f257fb\"}, {\"url\": \"https://git.kernel.org/stable/c/7f81f27b1093e4895e87b74143c59c055c3b1906\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ntracing: Fix use-after-free in print_graph_function_flags during tracer switching\\n\\nKairui reported a UAF issue in print_graph_function_flags() during\\nftrace stress testing [1]. This issue can be reproduced if puting a\\n\u0027mdelay(10)\u0027 after \u0027mutex_unlock(\u0026trace_types_lock)\u0027 in s_start(),\\nand executing the following script:\\n\\n  $ echo function_graph \u003e current_tracer\\n  $ cat trace \u003e /dev/null \u0026\\n  $ sleep 5  # Ensure the \u0027cat\u0027 reaches the \u0027mdelay(10)\u0027 point\\n  $ echo timerlat \u003e current_tracer\\n\\nThe root cause lies in the two calls to print_graph_function_flags\\nwithin print_trace_line during each s_show():\\n\\n  * One through \u0027iter-\u003etrace-\u003eprint_line()\u0027;\\n  * Another through \u0027event-\u003efuncs-\u003etrace()\u0027, which is hidden in\\n    print_trace_fmt() before print_trace_line returns.\\n\\nTracer switching only updates the former, while the latter continues\\nto use the print_line function of the old tracer, which in the script\\nabove is print_graph_function_flags.\\n\\nMoreover, when switching from the \u0027function_graph\u0027 tracer to the\\n\u0027timerlat\u0027 tracer, s_start only calls graph_trace_close of the\\n\u0027function_graph\u0027 tracer to free \u0027iter-\u003eprivate\u0027, but does not set\\nit to NULL. This provides an opportunity for \u0027event-\u003efuncs-\u003etrace()\u0027\\nto use an invalid \u0027iter-\u003eprivate\u0027.\\n\\nTo fix this issue, set \u0027iter-\u003eprivate\u0027 to NULL immediately after\\nfreeing it in graph_trace_close(), ensuring that an invalid pointer\\nis not passed to other tracers. Additionally, clean up the unnecessary\\n\u0027iter-\u003eprivate = NULL\u0027 during each \u0027cat trace\u0027 when using wakeup and\\nirqsoff tracers.\\n\\n [1] https://lore.kernel.org/all/20231112150030.84609-1-ryncsn@gmail.com/\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.292\", \"versionStartIncluding\": \"5.4.255\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.236\", \"versionStartIncluding\": \"5.10.193\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.180\", \"versionStartIncluding\": \"5.15.129\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.134\", \"versionStartIncluding\": \"6.1.50\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.87\", \"versionStartIncluding\": \"6.5\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12.23\", \"versionStartIncluding\": \"6.5\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.13.11\", \"versionStartIncluding\": \"6.5\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.14.2\", \"versionStartIncluding\": \"6.5\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.15\", \"versionStartIncluding\": \"6.5\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"4.14.324\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"4.19.293\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"6.4.13\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:56:07.902Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2025-22035\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:56:07.902Z\", \"dateReserved\": \"2024-12-29T08:45:45.809Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2025-04-16T14:11:53.958Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…