SB20250227130 - Input validation error in Linux kernel trace
Published: February 27, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-21777)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the rb_range_buffer(), rb_meta_valid(), rb_meta_init_text_addr() and rb_range_meta_init() functions in kernel/trace/ring_buffer.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0d547a6f5e8fad26ebc12f501d7d19fccdbad6bf
- https://git.kernel.org/stable/c/3ec743d558f111d8999aea24577ba66c65ee2eeb
- https://git.kernel.org/stable/c/f5b95f1fa2ef3a03f49eeec658ba97e721412b32
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.16
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14