In the Linux kernel, the following vulnerability has been resolved:
netfilter: use get_random_u32 instead of prandom
bh might occur while updating per-cpu rnd_state from user context, ie. local_out path.
BUG: using smp_processor_id() in preemptible [00000000] code: nginx/2725 caller is nft_ng_random_eval+0x24/0x54 [nft_numgen] Call Trace: check_preemption_disabled+0xde/0xe0 nft_ng_random_eval+0x24/0x54 [nft_numgen]
Use the random driver instead, this also avoids need for local prandom state. Moreover, prandom now uses the random driver since d4150779e60f ("random32: use real rng for non-deterministic randomness").
Based on earlier patch from Pablo Neira.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade bpftool-debuginfoUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-headersUpgrade perf-debuginfoUpgrade kernel-debuginfoUpgrade kernel-toolsUpgrade kernel-develUpgrade python-perfUpgrade kernel-livepatch-5.15.54-25.126Upgrade kernel-tools-debuginfoUpgrade perfUpgrade kernelUpgrade bpftoolUpgrade kernel-tools-develUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-livepatch-5.10.130-118.517Upgrade python-perf-debuginfo | May 22, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernel-abi-stablelistsUpgrade kernelUpgrade kernel-tools-libsUpgrade python3-perfUpgrade kernel-toolsUpgrade bpftool | Jul 1, 2025 | Feb 26, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linux-image-5.4.0-225-genericUpgrade linux-image-raspi-5.4Upgrade linux-image-generic-lpae-5.4Upgrade linux-image-5.4.0-1137-raspiUpgrade linux-image-azure-fips-5.4Upgrade linux-image-gcpUpgrade linux-image-gcp-5.4Upgrade linux-image-5.4.0-1128-fipsUpgrade linux-image-raspi-hwe-18.04Upgrade linux-image-gcp-fipsUpgrade linux-image-fips-5.4Upgrade linux-image-5.4.0-1158-azure-fipsUpgrade linux-image-generic-hwe-18.04Upgrade linux-image-oem-osp1Upgrade linux-image-5.4.0-225-lowlatencyUpgrade linux-image-5.4.0-1100-ibmUpgrade linux-image-awsUpgrade linux-image-azureUpgrade linux-image-raspiUpgrade linux-image-azure-fipsUpgrade linux-image-5.4.0-1141-kvmUpgrade linux-image-virtual-hwe-18.04Upgrade linux-image-5.4.0-225-generic-lpaeUpgrade linux-image-raspi2Upgrade linux-image-kvmUpgrade linux-image-5.4.0-1157-gcp-fipsUpgrade linux-image-lowlatency-hwe-18.04Upgrade linux-image-lowlatency-5.4Upgrade linux-image-5.4.0-1072-xilinx-zynqmpUpgrade linux-image-generic-lpaeUpgrade linux-image-5.4.0-1152-oracleUpgrade linux-image-virtualUpgrade linux-image-oemUpgrade linux-image-xilinx-zynqmpUpgrade linux-image-gcp-fips-5.4Upgrade linux-image-azure-5.4Upgrade linux-image-xilinx-zynqmp-5.4Upgrade linux-image-aws-5.4Upgrade linux-image-azure-lts-20.04Upgrade linux-image-snapdragon-5.4Upgrade linux-image-oracle-lts-20.04Upgrade linux-image-5.4.0-1058-iotUpgrade linux-image-oracle-5.4Upgrade linux-image-bluefield-5.4Upgrade linux-image-genericUpgrade linux-image-5.4.0-1154-aws-fipsUpgrade linux-image-ibm-lts-20.04Upgrade linux-image-aws-fips-5.4Upgrade linux-image-ibmUpgrade linux-image-5.4.0-1116-bluefieldUpgrade linux-image-5.4.0-1157-azureUpgrade linux-image-fipsUpgrade linux-image-5.4.0-1154-awsUpgrade linux-image-oracleUpgrade linux-image-aws-lts-20.04Upgrade linux-image-gcp-lts-20.04Upgrade linux-image-lowlatencyUpgrade linux-image-virtual-5.4Upgrade linux-image-generic-5.4Upgrade linux-image-ibm-edgeUpgrade linux-image-ibm-5.4Upgrade linux-image-aws-fipsUpgrade linux-image-bluefieldUpgrade linux-image-kvm-5.4Upgrade linux-image-snapdragon-hwe-18.04Upgrade linux-image-5.4.0-1157-gcp | Mar 19, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub