SB2025062053 - Improper locking in Linux kernel kernel probes
Published: June 20, 2025 Updated: June 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2022-50225)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the arch_uprobe_pre_xol(), arch_uprobe_post_xol() and arch_uprobe_abort_xol() functions in arch/riscv/kernel/probes/uprobes.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3811d51778900064d27d8c9a98f73410fb3b471d
- https://git.kernel.org/stable/c/3dbe5829408bc1586f75b4667ef60e5aab0209c7
- https://git.kernel.org/stable/c/73fc099eaefd9a92c83b6c07dad066411fd5a192
- https://git.kernel.org/stable/c/c71e000db8536d27ec410abb3e314896a78b4f19
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.61