PT-2025-27982 · Linux+1 · Linux Kernel+1

Published

2025-05-29

·

Updated

2026-05-26

·

CVE-2025-38207

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to the fixed version
Description: A vulnerability in the Linux kernel has been resolved, related to the mm module, specifically with the uprobe functionality. The issue occurs when expanding a vma (virtual memory area), causing the uprobe pte (page table entry) to be overwritten, leading to an orphan pte. This problem was first found in linux-6.6.y and also exists in the community syzkaller. The vulnerability can be reproduced by registering an uprobe on a file at zero offset, mapping the file, and then remapping part of the vma to a new location.
Recommendations: For Linux kernel versions prior to the fixed version, consider applying the patch series "Fix uprobe pte be overwritten when expanding vma" to resolve the issue. As a temporary workaround, avoid using the uprobe functionality on files at zero offset to minimize the risk of exploitation. Restrict access to the mm module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2025-15459
CVE-2025-38207
ECHO-2C8A-A987-7E55
OESA-2025-1959
OESA-2025-1960
OESA-2025-1961

Affected Products

Debian
Linux Kernel