In the Linux kernel, the following vulnerability has been resolved:
tracing/eprobes: Have event probes be consistent with kprobes and uprobes
Currently, if a symbol "@" is attempted to be used with an event probe (eprobes), it will cause a NULL pointer dereference crash.
Both kprobes and uprobes can reference data other than the main registers. Such as immediate address, symbols and the current task name. Have eprobes do the same thing.
For "comm", if "comm" is used and the event being attached to does not have the "comm" field, then make it the "$comm" that kprobes has. This is consistent to the way histograms and filters work.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-x86_64Upgrade bpftoolUpgrade bpftool-debuginfoUpgrade kernel-headersUpgrade kernel-tools-debuginfoUpgrade kernel-livepatch-5.15.69-37.134Upgrade kernelUpgrade python-perf-debuginfoUpgrade kernel-debuginfoUpgrade kernel-develUpgrade kernel-toolsUpgrade perfUpgrade perf-debuginfoUpgrade kernel-tools-develUpgrade python-perfUpgrade kernel-debuginfo-common-aarch64 | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade linux | Jun 20, 2025 | Jun 20, 2025 |
| Ubuntu | — | Upgrade linux-azure-5.15Upgrade linux-oracleUpgrade linux-intel-iotgUpgrade linuxUpgrade linux-kvmUpgrade linux-gcp-5.15Upgrade linux-ibmUpgrade linux-oracle-5.15Upgrade linux-lowlatencyUpgrade linux-intel-iotg-5.15Upgrade linux-nvidiaUpgrade linux-riscv-5.15Upgrade linux-gkeopUpgrade linux-realtimeUpgrade linux-awsUpgrade linux-gkeUpgrade linux-azure-fdeUpgrade linux-azureUpgrade linux-gcpUpgrade linux-hwe-5.15Upgrade linux-raspiUpgrade linux-lowlatency-hwe-5.15Upgrade linux-aws-5.15 | Jun 26, 2025 | Jun 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub