目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-38424— Linux kernel 安全漏洞

AI 预测 4.4 利用难度: 中等 EPSS 0.17% · P7

影响版本矩阵 18

厂商产品版本范围状态
LinuxLinuxc5ebcedb566ef17bda7b02686e0d658a7bb42ee7< 7b8f3c72175c6a63a95cf2e219f8b78e2baad34eaffected
c5ebcedb566ef17bda7b02686e0d658a7bb42ee7< 507c9a595bad3abd107c6a8857d7fd125d89f386affected
c5ebcedb566ef17bda7b02686e0d658a7bb42ee7< a9f6aab7910a0ef2895797f15c947f6d1053160faffected
c5ebcedb566ef17bda7b02686e0d658a7bb42ee7< 975ffddfa2e19823c719459d2364fcaa17673964affected
c5ebcedb566ef17bda7b02686e0d658a7bb42ee7< 2ee6044a693735396bb47eeaba1ac3ae26c1c99baffected
c5ebcedb566ef17bda7b02686e0d658a7bb42ee7< 456019adaa2f5366b89c868dea9b483179bece54affected
c5ebcedb566ef17bda7b02686e0d658a7bb42ee7< 7311970d07c4606362081250da95f2c7901fc0dbaffected
c5ebcedb566ef17bda7b02686e0d658a7bb42ee7< 4f6fc782128355931527cefe3eb45338abd8ab39affected
… +10 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-38424 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
perf: Fix sample vs do_exit()
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: perf: Fix sample vs do_exit() Baisheng Gao reported an ARM64 crash, which Mark decoded as being a synchronous external abort -- most likely due to trying to access MMIO in bad ways. The crash further shows perf trying to do a user stack sample while in exit_mmap()'s tlb_finish_mmu() -- i.e. while tearing down the address space it is trying to access. It turns out that we stop perf after we tear down the userspace mm; a receipie for disaster, since perf likes to access userspace for various reasons. Flip this order by moving up where we stop perf in do_exit(). Additionally, harden PERF_SAMPLE_CALLCHAIN and PERF_SAMPLE_STACK_USER to abort when the current task does not have an mm (exit_mm() makes sure to set current->mm = NULL; before commencing with the actual teardown). Such that CPU wide events don't trip on this same problem.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于perf模块在do_exit期间尝试用户栈采样,可能导致内存访问错误。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 ~ 7b8f3c72175c6a63a95cf2e219f8b78e2baad34e -
LinuxLinux 3.7 -

二、漏洞 CVE-2025-38424 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-38424 的情报信息

登录查看更多情报信息。

同批安全公告 · Linux · 2025-07-25 · 共 114 条

CVE-2025-38426Linux kernel 安全漏洞
CVE-2025-38440Linux kernel 安全漏洞
CVE-2025-38438Linux kernel 安全漏洞
CVE-2025-38437Linux kernel 安全漏洞
CVE-2025-38436Linux kernel 安全漏洞
CVE-2025-38435Linux kernel 安全漏洞
CVE-2025-38434Linux kernel 安全漏洞
CVE-2025-38433Linux kernel 安全漏洞
CVE-2025-38432Linux kernel 安全漏洞
CVE-2025-38431Linux kernel 安全漏洞
CVE-2025-38430Linux kernel 安全漏洞
CVE-2025-38429Linux kernel 安全漏洞
CVE-2025-38428Linux kernel 安全漏洞
CVE-2025-38427Linux kernel 安全漏洞
CVE-2025-38425Linux kernel 安全漏洞
CVE-2025-38413Linux kernel 安全漏洞
CVE-2025-38416Linux kernel 安全漏洞
CVE-2025-38415Linux kernel 安全漏洞
CVE-2025-38414Linux kernel 安全漏洞
CVE-2025-38417Linux kernel 安全漏洞

显示前 20 条,共 114 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38424

暂无评论


发表评论