CVE-2025-68216

Linux Kernel - Denial of Service via LoongArch BPF Trampoline Module Attachment

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Disable trampoline for kernel module function trace The current LoongArch BPF trampoline implementation is incompatible with tracing functions in kernel modules. This causes several severe and user-visible problems: * The `bpf_selftests/module_attach` test fails consistently. * Kernel lockup when a BPF program is attached to a module function [1]. * Critical kernel modules like WireGuard experience traffic disruption when their functions are traced with fentry [2]. Given the severity and the potential for other unknown side-effects, it is safest to disable the feature entirely for now. This patch prevents the BPF subsystem from allowing trampoline attachments to kernel module functions on LoongArch. This is a temporary mitigation until the core issues in the trampoline code for kernel module handling can be identified and fixed. [root@fedora bpf]# ./test_progs -a module_attach -v bpf_testmod.ko is already unloaded. Loading bpf_testmod.ko... Successfully loaded bpf_testmod.ko. test_module_attach:PASS:skel_open 0 nsec test_module_attach:PASS:set_attach_target 0 nsec test_module_attach:PASS:set_attach_target_explicit 0 nsec test_module_attach:PASS:skel_load 0 nsec libbpf: prog 'handle_fentry': failed to attach: -ENOTSUPP libbpf: prog 'handle_fentry': failed to auto-attach: -ENOTSUPP test_module_attach:FAIL:skel_attach skeleton attach failed: -524 Summary: 0/0 PASSED, 0 SKIPPED, 1 FAILED Successfully unloaded bpf_testmod.ko. [1]: https://lore.kernel.org/loongarch/CAK3+h2wDmpC-hP4u4pJY8T-yfKyk4yRzpu2LMO+C13FMT58oqQ@mail.gmail.com/ [2]: https://lore.kernel.org/loongarch/CAK3+h2wYcpc+OwdLDUBvg2rF9rvvyc5amfHT-KcFaK93uoELPg@mail.gmail.com/

Scores

EPSS 0.0003
EPSS Percentile 8.0%

Details

Status published
Products (7)
linux/Kernel 6.17.0 - 6.17.10linux
Linux/Linux < 6.17
Linux/Linux 6.17
Linux/Linux 6.17.10 - 6.17.*
Linux/Linux 6.18
Linux/Linux f9b6b41f0cf31791541cea9644ddbedb46465801 - 44eb3849378be5f72b8be03edbacbdcd6f5eade4
Linux/Linux f9b6b41f0cf31791541cea9644ddbedb46465801 - 677e6123e3d24adaa252697dc89740f2ac07664e
Published Dec 16, 2025
Tracked Since Feb 18, 2026