CVE-2025-38202
MEDIUMLinux Kernel - Use-After-Free in bpf_map_lookup_percpu_elem
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() bpf_map_lookup_percpu_elem() helper is also available for sleepable bpf program. When BPF JIT is disabled or under 32-bit host, bpf_map_lookup_percpu_elem() will not be inlined. Using it in a sleepable bpf program will trigger the warning in bpf_map_lookup_percpu_elem(), because the bpf program only holds rcu_read_lock_trace lock. Therefore, add the missed check.
References (6)
Core 6
Core References
Third Party Advisory, Mailing List
https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
Scores
CVSS v3
5.5
EPSS
0.0007
EPSS Percentile
21.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (18)
debian/debian_linux
11.0
linux/Kernel
5.19.0 - 6.1.142linux
linux/Kernel
6.13.0 - 6.15.4linux
linux/Kernel
6.2.0 - 6.6.95linux
linux/Kernel
6.7.0 - 6.12.35linux
Linux/Linux
< 5.19
Linux/Linux
07343110b293456d30393e89b86c4dee1ac051c8 - 2d834477bbc1e8b8a59ff8b0c081529d6bed7b22
Linux/Linux
07343110b293456d30393e89b86c4dee1ac051c8 - 2f8c69a72e8ad87b36b8052f789da3cc2b2e186c
Linux/Linux
07343110b293456d30393e89b86c4dee1ac051c8 - 7bf4461f1c97207fda757014690d55a447ce859f
Linux/Linux
07343110b293456d30393e89b86c4dee1ac051c8 - b522d4d334f206284b1a44b0b0b2f99fd443b39b
... and 8 more
Published
Jul 04, 2025
Tracked Since
Feb 18, 2026