In the Linux kernel, the following vulnerability has been resolved:
netfilter: use get_random_u32 instead of prandom
bh might occur while updating per-cpu rnd_state from user context, ie. local_out path.
BUG: using smp_processor_id() in preemptible [00000000] code: nginx/2725 caller is nft_ng_random_eval+0x24/0x54 [nft_numgen] Call Trace: check_preemption_disabled+0xde/0xe0 nft_ng_random_eval+0x24/0x54 [nft_numgen]
Use the random driver instead, this also avoids need for local prandom state. Moreover, prandom now uses the random driver since d4150779e60f ("random32: use real rng for non-deterministic randomness").
Based on earlier patch from Pablo Neira.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-tools-develUpgrade python-perf-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernelUpgrade kernel-livepatch-5.10.130-118.517Upgrade bpftoolUpgrade kernel-debuginfoUpgrade python-perfUpgrade kernel-toolsUpgrade perf-debuginfoUpgrade kernel-livepatch-5.15.54-25.126Upgrade kernel-develUpgrade bpftool-debuginfoUpgrade perfUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-headers | May 22, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernelUpgrade kernel-abi-stablelistsUpgrade kernel-toolsUpgrade bpftoolUpgrade python3-perfUpgrade kernel-tools-libs | Jul 1, 2025 | Feb 26, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linux-image-5.4.0-1072-xilinx-zynqmpUpgrade linux-image-oracleUpgrade linux-image-generic-5.4Upgrade linux-image-aws-lts-20.04Upgrade linux-image-oemUpgrade linux-image-5.4.0-1154-awsUpgrade linux-image-xilinx-zynqmp-5.4Upgrade linux-image-gcp-fips-5.4Upgrade linux-image-gcp-lts-20.04Upgrade linux-image-lowlatencyUpgrade linux-image-5.4.0-1116-bluefieldUpgrade linux-image-5.4.0-1157-azureUpgrade linux-image-xilinx-zynqmpUpgrade linux-image-bluefield-5.4Upgrade linux-image-snapdragon-hwe-18.04Upgrade linux-image-generic-lpaeUpgrade linux-image-5.4.0-1152-oracleUpgrade linux-image-5.4.0-1157-gcpUpgrade linux-image-kvm-5.4Upgrade linux-image-oracle-lts-20.04Upgrade linux-image-aws-5.4Upgrade linux-image-fipsUpgrade linux-image-snapdragon-5.4Upgrade linux-image-ibm-5.4Upgrade linux-image-azure-5.4Upgrade linux-image-aws-fipsUpgrade linux-image-bluefieldUpgrade linux-image-5.4.0-1058-iotUpgrade linux-image-5.4.0-1154-aws-fipsUpgrade linux-image-ibm-lts-20.04Upgrade linux-image-ibmUpgrade linux-image-oracle-5.4Upgrade linux-image-virtual-5.4Upgrade linux-image-genericUpgrade linux-image-azure-lts-20.04Upgrade linux-image-ibm-edgeUpgrade linux-image-virtualUpgrade linux-image-aws-fips-5.4Upgrade linux-image-lowlatency-5.4Upgrade linux-image-fips-5.4Upgrade linux-image-5.4.0-1128-fipsUpgrade linux-image-gcp-5.4Upgrade linux-image-oem-osp1Upgrade linux-image-virtual-hwe-18.04Upgrade linux-image-generic-lpae-5.4Upgrade linux-image-azure-fips-5.4Upgrade linux-image-5.4.0-1137-raspiUpgrade linux-image-raspi2Upgrade linux-image-raspiUpgrade linux-image-5.4.0-225-lowlatencyUpgrade linux-image-raspi-hwe-18.04Upgrade linux-image-azureUpgrade linux-image-kvmUpgrade linux-image-azure-fipsUpgrade linux-image-lowlatency-hwe-18.04Upgrade linux-image-gcpUpgrade linux-image-gcp-fipsUpgrade linux-image-5.4.0-225-generic-lpaeUpgrade linux-image-generic-hwe-18.04Upgrade linux-image-5.4.0-1158-azure-fipsUpgrade linux-image-5.4.0-1157-gcp-fipsUpgrade linux-image-5.4.0-1100-ibmUpgrade linux-image-5.4.0-1141-kvmUpgrade linux-image-awsUpgrade linux-image-5.4.0-225-genericUpgrade linux-image-raspi-5.4 | Mar 19, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub