CVE-2025-40151
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: No support of struct argument in trampoline programs
The current implementation does not support struct argument. This causes a oops when running bpf selftest:
Reject it for now.
Detalles técnicos trazas, registros y código del informe original
$ ./test_progs -a tracing_struct
Oops[#1]:
CPU -1 Unable to handle kernel paging request at virtual address 0000000000000018, era == 9000000085bef268, ra == 90000000844f3938
rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: 1-...0: (19 ticks this GP) idle=1094/1/0x4000000000000000 softirq=1380/1382 fqs=801
rcu: (detected by 0, t=5252 jiffies, g=1197, q=52 ncpus=4)
Sending NMI from CPU 0 to CPUs 1:
rcu: rcu_preempt kthread starved for 2495 jiffies! g1197 f0x0 RCU_GP_DOING_FQS(6) ->state=0x0 ->cpu=2
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:I stack:0 pid:15 tgid:15 ppid:2 task_flags:0x208040 flags:0x00000800
Stack : 9000000100423e80 0000000000000402 0000000000000010 90000001003b0680
9000000085d88000 0000000000000000 0000000000000040 9000000087159350
9000000085c2b9b0 0000000000000001 900000008704a000 0000000000000005
00000000ffff355b 00000000ffff355b 0000000000000000 0000000000000004
9000000085d90510 0000000000000000 0000000000000002 7b5d998f8281e86e
00000000ffff355c 7b5d998f8281e86e 000000000000003f 9000000087159350
900000008715bf98 0000000000000005 9000000087036000 900000008704a000
9000000100407c98 90000001003aff80 900000008715c4c0 9000000085c2b9b0
00000000ffff355b 9000000085c33d3c 00000000000000b4 0000000000000000
9000000007002150 00000000ffff355b 9000000084615480 0000000007000002
...
Call Trace:
[<9000000085c2a868>] __schedule+0x410/0x1520
[<9000000085c2b9ac>] schedule+0x34/0x190
[<9000000085c33d38>] schedule_timeout+0x98/0x140
[<90000000845e9120>] rcu_gp_fqs_loop+0x5f8/0x868
[<90000000845ed538>] rcu_gp_kthread+0x260/0x2e0
[<900000008454e8a4>] kthread+0x144/0x238
[<9000000085c26b60>] ret_from_kernel_thread+0x28/0xc8
[<90000000844f20e4>] ret_from_kernel_thread_asm+0xc/0x88
rcu: Stack dump where RCU GP kthread last ran:
Sending NMI from CPU 0 to CPUs 2:
NMI backtrace for cpu 2 skipped: idling at idle_exit+0x0/0x4CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.14%
- Percentil entre todas las CVEs puntuadas: 3
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact75 %
Vulnerabilidad local en kernel Linux (AV:L/PR:L) que causa un oops (kernel panic) al procesar argumentos struct en programas BPF trampoline, resultando en denegación de servicio.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-40151",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "f9b6b41f0cf31791541cea9644ddbedb46465801",
"lessThan": "d1158559315143e11bfaabcd4b2bea98c7ed1be9",
"versionType": "git"
},
{
"status": "affected",
"version": "f9b6b41f0cf31791541cea9644ddbedb46465801",
"lessThan": "e82406c7cbdd368c5459b8a45e118811d2ba0794",
"versionType": "git"
}
],
"programFiles": [
"arch/loongarch/net/bpf_jit.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.17.3",
"versionType": "semver",
"lessThanOrEqual": "6.17.*"
},
{
"status": "unaffected",
"version": "6.18",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/loongarch/net/bpf_jit.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-11-12T11:15:45.033",
"references": [
{
"url": "https://git.kernel.org/stable/c/d1158559315143e11bfaabcd4b2bea98c7ed1be9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e82406c7cbdd368c5459b8a45e118811d2ba0794",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: No support of struct argument in trampoline programs\n\nThe current implementation does not support struct argument. This causes\na oops when running bpf selftest:\n\n $ ./test_progs -a tracing_struct\n Oops[#1]:\n CPU -1 Unable to handle kernel paging request at virtual address 0000000000000018, era == 9000000085bef268, ra == 90000000844f3938\n rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:\n rcu: 1-...0: (19 ticks this GP) idle=1094/1/0x4000000000000000 softirq=1380/1382 fqs=801\n rcu: (detected by 0, t=5252 jiffies, g=1197, q=52 ncpus=4)\n Sending NMI from CPU 0 to CPUs 1:\n rcu: rcu_preempt kthread starved for 2495 jiffies! g1197 f0x0 RCU_GP_DOING_FQS(6) ->state=0x0 ->cpu=2\n rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.\n rcu: RCU grace-period kthread stack dump:\n task:rcu_preempt state:I stack:0 pid:15 tgid:15 ppid:2 task_flags:0x208040 flags:0x00000800\n Stack : 9000000100423e80 0000000000000402 0000000000000010 90000001003b0680\n 9000000085d88000 0000000000000000 0000000000000040 9000000087159350\n 9000000085c2b9b0 0000000000000001 900000008704a000 0000000000000005\n 00000000ffff355b 00000000ffff355b 0000000000000000 0000000000000004\n 9000000085d90510 0000000000000000 0000000000000002 7b5d998f8281e86e\n 00000000ffff355c 7b5d998f8281e86e 000000000000003f 9000000087159350\n 900000008715bf98 0000000000000005 9000000087036000 900000008704a000\n 9000000100407c98 90000001003aff80 900000008715c4c0 9000000085c2b9b0\n 00000000ffff355b 9000000085c33d3c 00000000000000b4 0000000000000000\n 9000000007002150 00000000ffff355b 9000000084615480 0000000007000002\n ...\n Call Trace:\n [<9000000085c2a868>] __schedule+0x410/0x1520\n [<9000000085c2b9ac>] schedule+0x34/0x190\n [<9000000085c33d38>] schedule_timeout+0x98/0x140\n [<90000000845e9120>] rcu_gp_fqs_loop+0x5f8/0x868\n [<90000000845ed538>] rcu_gp_kthread+0x260/0x2e0\n [<900000008454e8a4>] kthread+0x144/0x238\n [<9000000085c26b60>] ret_from_kernel_thread+0x28/0xc8\n [<90000000844f20e4>] ret_from_kernel_thread_asm+0xc/0x88\n\n rcu: Stack dump where RCU GP kthread last ran:\n Sending NMI from CPU 0 to CPUs 2:\n NMI backtrace for cpu 2 skipped: idling at idle_exit+0x0/0x4\n\nReject it for now."
}
],
"lastModified": "2026-07-30T06:24:13.977",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}