In the Linux kernel, the following vulnerability has been resolved:
cfi: Fix __cfi_slowpath_diag RCU usage with cpuidle
RCU_NONIDLE usage during __cfi_slowpath_diag can result in an invalid RCU state in the cpuidle code path:
WARNING: CPU: 1 PID: 0 at kernel/rcu/tree.c:613 rcu_eqs_enter+0xe4/0x138 ... Call trace: rcu_eqs_enter+0xe4/0x138 rcu_idle_enter+0xa8/0x100 cpuidle_enter_state+0x154/0x3a8 cpuidle_enter+0x3c/0x58 do_idle.llvm.6590768638138871020+0x1f4/0x2ec cpu_startup_entry+0x28/0x2c secondary_start_kernel+0x1b8/0x220 __secondary_switched+0x94/0x98
Instead, call rcu_irq_enter/exit to wake up RCU only when needed and disable interrupts for the entire CFI shadow/module check when we do.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-x86_64Upgrade python-perf-debuginfoUpgrade kernel-headersUpgrade kernel-debuginfoUpgrade kernelUpgrade kernel-livepatch-5.15.50-23.125Upgrade perf-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-tools-debuginfoUpgrade python-perfUpgrade kernel-toolsUpgrade kernel-tools-develUpgrade perfUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-develUpgrade bpftool | May 22, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-awsUpgrade linux-intel-iotg-5.15Upgrade linux-azureUpgrade linux-raspiUpgrade linux-hwe-5.15Upgrade linuxUpgrade linux-azure-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-intel-iotgUpgrade linux-oracleUpgrade linux-riscv-5.15Upgrade linux-realtimeUpgrade linux-gcp-5.15Upgrade linux-gkeopUpgrade linux-oracle-5.15Upgrade linux-nvidiaUpgrade linux-kvmUpgrade linux-gkeUpgrade linux-ibmUpgrade linux-aws-5.15Upgrade linux-gcpUpgrade linux-lowlatency | Mar 19, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub