CVE-2025-37822 (GCVE-0-2025-37822)
Vulnerability from cvelistv5
Published
2025-05-08 06:26
Modified
2026-08-05 11:57
Summary
In the Linux kernel, the following vulnerability has been resolved: riscv: uprobes: Add missing fence.i after building the XOL buffer The XOL (execute out-of-line) buffer is used to single-step the replaced instruction(s) for uprobes. The RISC-V port was missing a proper fence.i (i$ flushing) after constructing the XOL buffer, which can result in incorrect execution of stale/broken instructions. This was found running the BPF selftests "test_progs: uprobe_autoattach, attach_probe" on the Spacemit K1/X60, where the uprobes tests randomly blew up.
Impacted products
Vendor Product Version
Linux Linux Version: 74784081aac8a0f3636965fc230e2d3b7cc123c6
Version: 74784081aac8a0f3636965fc230e2d3b7cc123c6
Version: 74784081aac8a0f3636965fc230e2d3b7cc123c6
Version: 74784081aac8a0f3636965fc230e2d3b7cc123c6
Version: 74784081aac8a0f3636965fc230e2d3b7cc123c6
Version: 74784081aac8a0f3636965fc230e2d3b7cc123c6
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "arch/riscv/kernel/probes/uprobes.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "be6d98766ac952d38241d5a5b213f363afa421c3",
              "status": "affected",
              "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
              "versionType": "git"
            },
            {
              "lessThan": "b6d8d4d01ca8514fa89b05355f296758a91e2297",
              "status": "affected",
              "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
              "versionType": "git"
            },
            {
              "lessThan": "77c956152a3a7c7a18b68f3654f70565b2181d03",
              "status": "affected",
              "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
              "versionType": "git"
            },
            {
              "lessThan": "bcf6d3158c5902d92b6d62335af4422b7bf7c4e2",
              "status": "affected",
              "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
              "versionType": "git"
            },
            {
              "lessThan": "1dbb95a36499374c51b47ee8ae258a8862c20978",
              "status": "affected",
              "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
              "versionType": "git"
            },
            {
              "lessThan": "7d1d19a11cfbfd8bae1d89cc010b2cc397cd0c48",
              "status": "affected",
              "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "arch/riscv/kernel/probes/uprobes.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.12"
            },
            {
              "lessThan": "5.12",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.200",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.163",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.121",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.26",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.14.*",
              "status": "unaffected",
              "version": "6.14.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.15",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.200",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.163",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.121",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.26",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14.5",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.15",
                  "versionStartIncluding": "5.12",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: uprobes: Add missing fence.i after building the XOL buffer\n\nThe XOL (execute out-of-line) buffer is used to single-step the\nreplaced instruction(s) for uprobes. The RISC-V port was missing a\nproper fence.i (i$ flushing) after constructing the XOL buffer, which\ncan result in incorrect execution of stale/broken instructions.\n\nThis was found running the BPF selftests \"test_progs:\nuprobe_autoattach, attach_probe\" on the Spacemit K1/X60, where the\nuprobes tests randomly blew up."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Exploitation requires local execution on the target \u2014 the attacker must run a process that executes the probed instruction and primes the I-cache at the user-mapped `[uprobes]` XOL page. There is no network-reachable path to `arch_uprobe_copy_ixol()`.\nAC:L - RISC-V has no implicit I$/D$ coherence, so the missing `fence.i` leaves stale lines as baseline architectural behavior, not a rare config; the attacker can trigger the XOL path repeatedly at will and can deliberately execute at the known, user-mapped XOL slot addresses to seed the stale lines. The bug was observed reproducing on stock hardware during ordinary selftest runs.\nPR:L - Once a uprobe is active \u2014 a routine observability configuration installed by an admin, not an attack step \u2014 an entirely unprivileged local user drives the vulnerable path just by calling the probed function in their own process. No capability is needed to reach `xol_get_insn_slot()` \u2192 `arch_uprobe_copy_ixol()`.\nUI:N - The attacker executes the probed instruction in its own process to trigger the XOL copy; no action by any other user or victim is required.\nS:U - The stale instruction executes in the traced process\u0027s own user context and the WARN/panic effects stay within the kernel\u0027s own authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The traced process \u2014 potentially a privileged daemon or setuid binary under a system-wide probe on libc/libssl \u2014 executes a stale instruction with its live register state, a control-flow-integrity failure that can branch into or read out that process\u0027s memory. The attacker influences what sits in the I-cache at that kernel-provided address.\nI:H - Executing a stale/wrong instruction with the probed process\u0027s live registers yields arbitrary stores and control-flow deviation inside that process, and the trailing ebreak may be skipped entirely, letting the PC run past the slot into adjacent slot contents.\nA:H - The probed process is killed via `force_sig(SIGILL)`, and the broken single-step contract hits `WARN_ON_ONCE` in both `arch_uprobe_post_xol()` and `handle_singlestep()`, which is a kernel panic under `panic_on_warn`. The commit reports uprobe selftests randomly blowing up on real hardware."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:57:45.691Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/be6d98766ac952d38241d5a5b213f363afa421c3"
        },
        {
          "url": "https://git.kernel.org/stable/c/b6d8d4d01ca8514fa89b05355f296758a91e2297"
        },
        {
          "url": "https://git.kernel.org/stable/c/77c956152a3a7c7a18b68f3654f70565b2181d03"
        },
        {
          "url": "https://git.kernel.org/stable/c/bcf6d3158c5902d92b6d62335af4422b7bf7c4e2"
        },
        {
          "url": "https://git.kernel.org/stable/c/1dbb95a36499374c51b47ee8ae258a8862c20978"
        },
        {
          "url": "https://git.kernel.org/stable/c/7d1d19a11cfbfd8bae1d89cc010b2cc397cd0c48"
        }
      ],
      "title": "riscv: uprobes: Add missing fence.i after building the XOL buffer",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-37822",
    "datePublished": "2025-05-08T06:26:16.209Z",
    "dateReserved": "2025-04-16T04:51:23.947Z",
    "dateUpdated": "2026-08-05T11:57:45.691Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…