Risk | Low |
Patch available | YES |
Number of vulnerabilities | 10 |
CVE-ID | CVE-2024-58098 CVE-2025-22079 CVE-2025-23146 CVE-2025-37807 CVE-2025-37818 CVE-2025-37830 CVE-2025-37870 CVE-2025-37878 CVE-2025-37884 CVE-2025-37938 |
CWE-ID | CWE-399 CWE-125 CWE-476 CWE-401 CWE-20 CWE-667 CWE-416 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
openEuler Operating systems & Components / Operating system python3-perf-debuginfo Operating systems & Components / Operating system package or component python3-perf Operating systems & Components / Operating system package or component perf-debuginfo Operating systems & Components / Operating system package or component perf Operating systems & Components / Operating system package or component kernel-tools-devel Operating systems & Components / Operating system package or component kernel-tools-debuginfo Operating systems & Components / Operating system package or component kernel-tools Operating systems & Components / Operating system package or component kernel-source Operating systems & Components / Operating system package or component kernel-headers Operating systems & Components / Operating system package or component kernel-devel Operating systems & Components / Operating system package or component kernel-debugsource Operating systems & Components / Operating system package or component kernel-debuginfo Operating systems & Components / Operating system package or component bpftool-debuginfo Operating systems & Components / Operating system package or component bpftool Operating systems & Components / Operating system package or component kernel Operating systems & Components / Operating system package or component |
Vendor | openEuler |
Security Bulletin
This security bulletin contains information about 10 vulnerabilities.
EUVDB-ID: #VU108686
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-58098
CWE-ID:
CWE-399 - Resource Management Errors
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the check_func_call(), mark_subprog_changes_pkt_data(), visit_func_call_insn() and visit_insn() functions in kernel/bpf/verifier.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsopenEuler: 24.03 LTS SP1
python3-perf-debuginfo: before 6.6.0-92.0.0.97
python3-perf: before 6.6.0-92.0.0.97
perf-debuginfo: before 6.6.0-92.0.0.97
perf: before 6.6.0-92.0.0.97
kernel-tools-devel: before 6.6.0-92.0.0.97
kernel-tools-debuginfo: before 6.6.0-92.0.0.97
kernel-tools: before 6.6.0-92.0.0.97
kernel-source: before 6.6.0-92.0.0.97
kernel-headers: before 6.6.0-92.0.0.97
kernel-devel: before 6.6.0-92.0.0.97
kernel-debugsource: before 6.6.0-92.0.0.97
kernel-debuginfo: before 6.6.0-92.0.0.97
bpftool-debuginfo: before 6.6.0-92.0.0.97
bpftool: before 6.6.0-92.0.0.97
kernel: before 6.6.0-92.0.0.97
CPE2.3https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1540
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU107689
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-22079
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the __ocfs2_find_path() function in fs/ocfs2/alloc.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsopenEuler: 24.03 LTS SP1
python3-perf-debuginfo: before 6.6.0-92.0.0.97
python3-perf: before 6.6.0-92.0.0.97
perf-debuginfo: before 6.6.0-92.0.0.97
perf: before 6.6.0-92.0.0.97
kernel-tools-devel: before 6.6.0-92.0.0.97
kernel-tools-debuginfo: before 6.6.0-92.0.0.97
kernel-tools: before 6.6.0-92.0.0.97
kernel-source: before 6.6.0-92.0.0.97
kernel-headers: before 6.6.0-92.0.0.97
kernel-devel: before 6.6.0-92.0.0.97
kernel-debugsource: before 6.6.0-92.0.0.97
kernel-debuginfo: before 6.6.0-92.0.0.97
bpftool-debuginfo: before 6.6.0-92.0.0.97
bpftool: before 6.6.0-92.0.0.97
kernel: before 6.6.0-92.0.0.97
CPE2.3https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1540
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU108468
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-23146
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the kb3930_probe() function in drivers/mfd/ene-kb3930.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsopenEuler: 24.03 LTS SP1
python3-perf-debuginfo: before 6.6.0-92.0.0.97
python3-perf: before 6.6.0-92.0.0.97
perf-debuginfo: before 6.6.0-92.0.0.97
perf: before 6.6.0-92.0.0.97
kernel-tools-devel: before 6.6.0-92.0.0.97
kernel-tools-debuginfo: before 6.6.0-92.0.0.97
kernel-tools: before 6.6.0-92.0.0.97
kernel-source: before 6.6.0-92.0.0.97
kernel-headers: before 6.6.0-92.0.0.97
kernel-devel: before 6.6.0-92.0.0.97
kernel-debugsource: before 6.6.0-92.0.0.97
kernel-debuginfo: before 6.6.0-92.0.0.97
bpftool-debuginfo: before 6.6.0-92.0.0.97
bpftool: before 6.6.0-92.0.0.97
kernel: before 6.6.0-92.0.0.97
CPE2.3https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1540
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU108788
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-37807
CWE-ID:
CWE-401 - Missing release of memory after effective lifetime
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the htab_is_percpu() and htab_percpu_map_gen_lookup() functions in kernel/bpf/hashtab.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsopenEuler: 24.03 LTS SP1
python3-perf-debuginfo: before 6.6.0-92.0.0.97
python3-perf: before 6.6.0-92.0.0.97
perf-debuginfo: before 6.6.0-92.0.0.97
perf: before 6.6.0-92.0.0.97
kernel-tools-devel: before 6.6.0-92.0.0.97
kernel-tools-debuginfo: before 6.6.0-92.0.0.97
kernel-tools: before 6.6.0-92.0.0.97
kernel-source: before 6.6.0-92.0.0.97
kernel-headers: before 6.6.0-92.0.0.97
kernel-devel: before 6.6.0-92.0.0.97
kernel-debugsource: before 6.6.0-92.0.0.97
kernel-debuginfo: before 6.6.0-92.0.0.97
bpftool-debuginfo: before 6.6.0-92.0.0.97
bpftool: before 6.6.0-92.0.0.97
kernel: before 6.6.0-92.0.0.97
CPE2.3https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1540
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU108814
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-37818
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the huge_pte_offset() function in arch/loongarch/mm/hugetlbpage.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsopenEuler: 24.03 LTS SP1
python3-perf-debuginfo: before 6.6.0-92.0.0.97
python3-perf: before 6.6.0-92.0.0.97
perf-debuginfo: before 6.6.0-92.0.0.97
perf: before 6.6.0-92.0.0.97
kernel-tools-devel: before 6.6.0-92.0.0.97
kernel-tools-debuginfo: before 6.6.0-92.0.0.97
kernel-tools: before 6.6.0-92.0.0.97
kernel-source: before 6.6.0-92.0.0.97
kernel-headers: before 6.6.0-92.0.0.97
kernel-devel: before 6.6.0-92.0.0.97
kernel-debugsource: before 6.6.0-92.0.0.97
kernel-debuginfo: before 6.6.0-92.0.0.97
bpftool-debuginfo: before 6.6.0-92.0.0.97
bpftool: before 6.6.0-92.0.0.97
kernel: before 6.6.0-92.0.0.97
CPE2.3https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1540
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU108806
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-37830
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the scmi_cpufreq_get_rate() function in drivers/cpufreq/scmi-cpufreq.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsopenEuler: 24.03 LTS SP1
python3-perf-debuginfo: before 6.6.0-92.0.0.97
python3-perf: before 6.6.0-92.0.0.97
perf-debuginfo: before 6.6.0-92.0.0.97
perf: before 6.6.0-92.0.0.97
kernel-tools-devel: before 6.6.0-92.0.0.97
kernel-tools-debuginfo: before 6.6.0-92.0.0.97
kernel-tools: before 6.6.0-92.0.0.97
kernel-source: before 6.6.0-92.0.0.97
kernel-headers: before 6.6.0-92.0.0.97
kernel-devel: before 6.6.0-92.0.0.97
kernel-debugsource: before 6.6.0-92.0.0.97
kernel-debuginfo: before 6.6.0-92.0.0.97
bpftool-debuginfo: before 6.6.0-92.0.0.97
bpftool: before 6.6.0-92.0.0.97
kernel: before 6.6.0-92.0.0.97
CPE2.3https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1540
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU108902
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-37870
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the dcn401_enable_stream() function in drivers/gpu/drm/amd/display/dc/hwss/dcn401/dcn401_hwseq.c, within the dcn20_enable_stream() function in drivers/gpu/drm/amd/display/dc/hwss/dcn20/dcn20_hwseq.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsopenEuler: 24.03 LTS SP1
python3-perf-debuginfo: before 6.6.0-92.0.0.97
python3-perf: before 6.6.0-92.0.0.97
perf-debuginfo: before 6.6.0-92.0.0.97
perf: before 6.6.0-92.0.0.97
kernel-tools-devel: before 6.6.0-92.0.0.97
kernel-tools-debuginfo: before 6.6.0-92.0.0.97
kernel-tools: before 6.6.0-92.0.0.97
kernel-source: before 6.6.0-92.0.0.97
kernel-headers: before 6.6.0-92.0.0.97
kernel-devel: before 6.6.0-92.0.0.97
kernel-debugsource: before 6.6.0-92.0.0.97
kernel-debuginfo: before 6.6.0-92.0.0.97
bpftool-debuginfo: before 6.6.0-92.0.0.97
bpftool: before 6.6.0-92.0.0.97
kernel: before 6.6.0-92.0.0.97
CPE2.3https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1540
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU108895
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-37878
CWE-ID:
CWE-399 - Resource Management Errors
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the inherit_event() function in kernel/events/core.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsopenEuler: 24.03 LTS SP1
python3-perf-debuginfo: before 6.6.0-92.0.0.97
python3-perf: before 6.6.0-92.0.0.97
perf-debuginfo: before 6.6.0-92.0.0.97
perf: before 6.6.0-92.0.0.97
kernel-tools-devel: before 6.6.0-92.0.0.97
kernel-tools-debuginfo: before 6.6.0-92.0.0.97
kernel-tools: before 6.6.0-92.0.0.97
kernel-source: before 6.6.0-92.0.0.97
kernel-headers: before 6.6.0-92.0.0.97
kernel-devel: before 6.6.0-92.0.0.97
kernel-debugsource: before 6.6.0-92.0.0.97
kernel-debuginfo: before 6.6.0-92.0.0.97
bpftool-debuginfo: before 6.6.0-92.0.0.97
bpftool: before 6.6.0-92.0.0.97
kernel: before 6.6.0-92.0.0.97
CPE2.3https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1540
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU108878
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-37884
CWE-ID:
CWE-667 - Improper Locking
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the __set_printk_clr_event() and bpf_get_trace_vprintk_proto() functions in kernel/trace/bpf_trace.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsopenEuler: 24.03 LTS SP1
python3-perf-debuginfo: before 6.6.0-92.0.0.97
python3-perf: before 6.6.0-92.0.0.97
perf-debuginfo: before 6.6.0-92.0.0.97
perf: before 6.6.0-92.0.0.97
kernel-tools-devel: before 6.6.0-92.0.0.97
kernel-tools-debuginfo: before 6.6.0-92.0.0.97
kernel-tools: before 6.6.0-92.0.0.97
kernel-source: before 6.6.0-92.0.0.97
kernel-headers: before 6.6.0-92.0.0.97
kernel-devel: before 6.6.0-92.0.0.97
kernel-debugsource: before 6.6.0-92.0.0.97
kernel-debuginfo: before 6.6.0-92.0.0.97
bpftool-debuginfo: before 6.6.0-92.0.0.97
bpftool: before 6.6.0-92.0.0.97
kernel: before 6.6.0-92.0.0.97
CPE2.3https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1540
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU109509
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-37938
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the test_event_printk() function in kernel/trace/trace_events.c. A local user can escalate privileges on the system.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsopenEuler: 24.03 LTS SP1
python3-perf-debuginfo: before 6.6.0-92.0.0.97
python3-perf: before 6.6.0-92.0.0.97
perf-debuginfo: before 6.6.0-92.0.0.97
perf: before 6.6.0-92.0.0.97
kernel-tools-devel: before 6.6.0-92.0.0.97
kernel-tools-debuginfo: before 6.6.0-92.0.0.97
kernel-tools: before 6.6.0-92.0.0.97
kernel-source: before 6.6.0-92.0.0.97
kernel-headers: before 6.6.0-92.0.0.97
kernel-devel: before 6.6.0-92.0.0.97
kernel-debugsource: before 6.6.0-92.0.0.97
kernel-debuginfo: before 6.6.0-92.0.0.97
bpftool-debuginfo: before 6.6.0-92.0.0.97
bpftool: before 6.6.0-92.0.0.97
kernel: before 6.6.0-92.0.0.97
CPE2.3https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1540
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.