Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-37822— riscv: uprobes: Add missing fence.i after building the XOL buffer

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于指令缓存未同步,可能导致执行错误指令。

CVSS 7.8 · High EPSS 0.27% · P17

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux 74784081aac8a0f3636965fc230e2d3b7cc123c6< be6d98766ac952d38241d5a5b213f363afa421c3 affected
74784081aac8a0f3636965fc230e2d3b7cc123c6< b6d8d4d01ca8514fa89b05355f296758a91e2297 affected
74784081aac8a0f3636965fc230e2d3b7cc123c6< 77c956152a3a7c7a18b68f3654f70565b2181d03 affected
74784081aac8a0f3636965fc230e2d3b7cc123c6< bcf6d3158c5902d92b6d62335af4422b7bf7c4e2 affected
74784081aac8a0f3636965fc230e2d3b7cc123c6< 1dbb95a36499374c51b47ee8ae258a8862c20978 affected
74784081aac8a0f3636965fc230e2d3b7cc123c6< 7d1d19a11cfbfd8bae1d89cc010b2cc397cd0c48 affected
5.12 affected
< 5.12 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-37822

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
riscv: uprobes: Add missing fence.i after building the XOL buffer
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: riscv: uprobes: Add missing fence.i after building the XOL buffer The XOL (execute out-of-line) buffer is used to single-step the replaced instruction(s) for uprobes. The RISC-V port was missing a proper fence.i (i$ flushing) after constructing the XOL buffer, which can result in incorrect execution of stale/broken instructions. This was found running the BPF selftests "test_progs: uprobe_autoattach, attach_probe" on the Spacemit K1/X60, where the uprobes tests randomly blew up.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于指令缓存未同步,可能导致执行错误指令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 74784081aac8a0f3636965fc230e2d3b7cc123c6 ~ be6d98766ac952d38241d5a5b213f363afa421c3 -
Linux Linux 5.12 -

II. Public POCs for CVE-2025-37822

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-37822

请登录查看更多情报信息。

Same Patch Batch · Linux · 2025-05-08 · 33 CVEs total

CVE-2025-37801 7.8 HIGH spi: spi-imx: Add check for spi_imx_setupxfer()
CVE-2025-37823 7.8 HIGH net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too
CVE-2025-37814 7.8 HIGH tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT
CVE-2025-37813 7.8 HIGH usb: xhci: Fix invalid pointer dereference in Etron workaround
CVE-2025-37820 7.5 HIGH xen-netfront: handle NULL returned by xdp_convert_buff_to_frame()
CVE-2025-37802 7.5 HIGH ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING"
CVE-2025-37800 7.1 HIGH driver core: fix potential NULL pointer dereference in dev_uevent()
CVE-2025-37831 cpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate()
CVE-2025-37830 cpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_get_rate()
CVE-2025-37829 cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate()
CVE-2025-37828 scsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort()
CVE-2025-37826 scsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer()
CVE-2025-37827 btrfs: zoned: return EIO on RAID1 block group write pointer mismatch
CVE-2025-37825 nvmet: fix out-of-bounds access in nvmet_enable_port
CVE-2025-37834 mm/vmscan: don't try to reclaim hwpoison folio
CVE-2025-37824 tipc: fix NULL pointer dereference in tipc_mon_reinit_self()
CVE-2025-37821 sched/eevdf: Fix se->slice being set to U64_MAX and resulting crash
CVE-2025-37833 net/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads
CVE-2025-37819 irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode()
CVE-2025-37817 mcb: fix a double free bug in chameleon_parse_gdd()

Showing top 20 of 33 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-37822

No comments yet


Leave a comment