PT-2025-8845 · Linux+4 · Linux Kernel+4

Steven Rostedt

·

Published

2025-01-23

·

Updated

2026-04-20

·

CVE-2025-21733

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version
Description A vulnerability in the Linux kernel has been resolved. The issue occurs when the timerlat tracer is started with the osnoise option OSNOISE WORKLOAD disabled, but then the option is enabled and timerlat is removed. The tracepoints that were enabled on timerlat registration do not get disabled, triggering a warning in the tracepoint code when timerlat is started again. To fix this, a global flag is set when the osnoise option is enabled, and this flag is used to disable the events when timerlat is removed.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for this vulnerability. As a temporary workaround, consider disabling the timerlat tracer until a patch is available. Additionally, restrict access to the /sys/kernel/tracing/osnoise/options and /sys/kernel/tracing/current tracer files to minimize the risk of exploitation. Avoid using the OSNOISE WORKLOAD option in the osnoise tracer until the issue is resolved.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11994
CVE-2025-21733
OESA-2025-1248
OESA-2025-1249
OPENSUSE-SU-2025_0847-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:0847-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_0847-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1
USN-7521-1
USN-7521-2
USN-7521-3
USN-7651-1
USN-7651-2
USN-7651-3
USN-7651-4
USN-7651-5
USN-7651-6
USN-7652-1
USN-7653-1
USN-7737-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu