CVE-2025-38202

MEDIUM

Linux Kernel - Use-After-Free in bpf_map_lookup_percpu_elem

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() bpf_map_lookup_percpu_elem() helper is also available for sleepable bpf program. When BPF JIT is disabled or under 32-bit host, bpf_map_lookup_percpu_elem() will not be inlined. Using it in a sleepable bpf program will trigger the warning in bpf_map_lookup_percpu_elem(), because the bpf program only holds rcu_read_lock_trace lock. Therefore, add the missed check.

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 21.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (18)
debian/debian_linux 11.0
linux/Kernel 5.19.0 - 6.1.142linux
linux/Kernel 6.13.0 - 6.15.4linux
linux/Kernel 6.2.0 - 6.6.95linux
linux/Kernel 6.7.0 - 6.12.35linux
Linux/Linux < 5.19
Linux/Linux 07343110b293456d30393e89b86c4dee1ac051c8 - 2d834477bbc1e8b8a59ff8b0c081529d6bed7b22
Linux/Linux 07343110b293456d30393e89b86c4dee1ac051c8 - 2f8c69a72e8ad87b36b8052f789da3cc2b2e186c
Linux/Linux 07343110b293456d30393e89b86c4dee1ac051c8 - 7bf4461f1c97207fda757014690d55a447ce859f
Linux/Linux 07343110b293456d30393e89b86c4dee1ac051c8 - b522d4d334f206284b1a44b0b0b2f99fd443b39b
... and 8 more
Published Jul 04, 2025
Tracked Since Feb 18, 2026