PT-2025-16709 · Linux+3 · Linux Kernel+3

Naresh Kamboju

·

Published

2025-03-19

·

Updated

2026-03-13

·

CVE-2025-22069

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version
Description A vulnerability in the Linux kernel has been resolved. The issue is related to the stack layout for constructing arguments for the ftrace return to handler function in the return to handler function, which does not match the arch ftrace regs structure of riscv, leading to unexpected results. This can cause a "Bad frame pointer" kernel warning. The vulnerability can be reproduced with a specific command sequence involving dynamic events and tracing.
Recommendations To resolve the issue, update to a version of the Linux kernel where the stack layout for constructing arguments for the ftrace return to handler function has been fixed to match the arch ftrace regs structure of riscv. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Exposure of Resource to Wrong Sphere

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-04378
CVE-2025-22069
USN-7594-1
USN-7594-2
USN-7594-3

Affected Products

Astra Linux
Debian
Linux Kernel
Ubuntu