PT-2025-16709 · Linux+3 · Linux Kernel+3
Naresh Kamboju
·
Published
2025-03-19
·
Updated
2026-03-13
·
CVE-2025-22069
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to the fixed version
Description
A vulnerability in the Linux kernel has been resolved. The issue is related to the stack layout for constructing arguments for the
ftrace return to handler function in the return to handler function, which does not match the arch ftrace regs structure of riscv, leading to unexpected results. This can cause a "Bad frame pointer" kernel warning. The vulnerability can be reproduced with a specific command sequence involving dynamic events and tracing.Recommendations
To resolve the issue, update to a version of the Linux kernel where the stack layout for constructing arguments for the
ftrace return to handler function has been fixed to match the arch ftrace regs structure of riscv.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Stack Overflow
Exposure of Resource to Wrong Sphere
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Linux Kernel
Ubuntu