U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

CVE-2025-38424 Detail

Description

In the Linux kernel, the following vulnerability has been resolved: perf: Fix sample vs do_exit() Baisheng Gao reported an ARM64 crash, which Mark decoded as being a synchronous external abort -- most likely due to trying to access MMIO in bad ways. The crash further shows perf trying to do a user stack sample while in exit_mmap()'s tlb_finish_mmu() -- i.e. while tearing down the address space it is trying to access. It turns out that we stop perf after we tear down the userspace mm; a receipie for disaster, since perf likes to access userspace for various reasons. Flip this order by moving up where we stop perf in do_exit(). Additionally, harden PERF_SAMPLE_CALLCHAIN and PERF_SAMPLE_STACK_USER to abort when the current task does not have an mm (exit_mm() makes sure to set current->mm = NULL; before commencing with the actual teardown). Such that CPU wide events don't trip on this same problem.


Metrics

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NIST CVSS score
NIST: NVD
N/A
NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
https://git.kernel.org/stable/c/2ee6044a693735396bb47eeaba1ac3ae26c1c99b kernel.org
https://git.kernel.org/stable/c/456019adaa2f5366b89c868dea9b483179bece54 kernel.org
https://git.kernel.org/stable/c/4f6fc782128355931527cefe3eb45338abd8ab39 kernel.org
https://git.kernel.org/stable/c/507c9a595bad3abd107c6a8857d7fd125d89f386 kernel.org
https://git.kernel.org/stable/c/7311970d07c4606362081250da95f2c7901fc0db kernel.org
https://git.kernel.org/stable/c/7b8f3c72175c6a63a95cf2e219f8b78e2baad34e kernel.org
https://git.kernel.org/stable/c/975ffddfa2e19823c719459d2364fcaa17673964 kernel.org
https://git.kernel.org/stable/c/a9f6aab7910a0ef2895797f15c947f6d1053160f kernel.org

Weakness Enumeration

CWE-ID CWE Name Source

Change History

1 change records found show changes

Quick Info

CVE Dictionary Entry:
CVE-2025-38424
NVD Published Date:
07/25/2025
NVD Last Modified:
07/25/2025
Source:
kernel.org