CVE-2025-37822

HIGH

Linux Kernel 5.12-6.14.4 - Unauthenticated DoS via RISC-V XOL Buffer Execution

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: riscv: uprobes: Add missing fence.i after building the XOL buffer The XOL (execute out-of-line) buffer is used to single-step the replaced instruction(s) for uprobes. The RISC-V port was missing a proper fence.i (i$ flushing) after constructing the XOL buffer, which can result in incorrect execution of stale/broken instructions. This was found running the BPF selftests "test_progs: uprobe_autoattach, attach_probe" on the Spacemit K1/X60, where the uprobes tests randomly blew up.

Scores

CVSS v3 7.8
EPSS 0.0021
EPSS Percentile 11.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (21)
linux/Kernel 5.12.0 - 5.15.200linux
linux/Kernel 5.16.0 - 6.1.163linux
linux/Kernel 6.13.0 - 6.14.5linux
linux/Kernel 6.2.0 - 6.6.121linux
linux/Kernel 6.7.0 - 6.12.26linux
Linux/Linux < 5.12
Linux/Linux 5.12
Linux/Linux 5.15.200 - 5.15.*
Linux/Linux 6.1.163 - 6.1.*
Linux/Linux 6.12.26 - 6.12.*
... and 11 more
Published May 08, 2025
Tracked Since Feb 18, 2026