{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-37822",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-04-16T04:51:23.947Z",
        "datePublished": "2025-05-08T06:26:16.209Z",
        "dateUpdated": "2026-08-05T11:57:45.691Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:57:45.691Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: uprobes: Add missing fence.i after building the XOL buffer\n\nThe XOL (execute out-of-line) buffer is used to single-step the\nreplaced instruction(s) for uprobes. The RISC-V port was missing a\nproper fence.i (i$ flushing) after constructing the XOL buffer, which\ncan result in incorrect execution of stale/broken instructions.\n\nThis was found running the BPF selftests \"test_progs:\nuprobe_autoattach, attach_probe\" on the Spacemit K1/X60, where the\nuprobes tests randomly blew up."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - Exploitation requires local execution on the target — the attacker must run a process that executes the probed instruction and primes the I-cache at the user-mapped `[uprobes]` XOL page. There is no network-reachable path to `arch_uprobe_copy_ixol()`.\nAC:L - RISC-V has no implicit I$/D$ coherence, so the missing `fence.i` leaves stale lines as baseline architectural behavior, not a rare config; the attacker can trigger the XOL path repeatedly at will and can deliberately execute at the known, user-mapped XOL slot addresses to seed the stale lines. The bug was observed reproducing on stock hardware during ordinary selftest runs.\nPR:L - Once a uprobe is active — a routine observability configuration installed by an admin, not an attack step — an entirely unprivileged local user drives the vulnerable path just by calling the probed function in their own process. No capability is needed to reach `xol_get_insn_slot()` → `arch_uprobe_copy_ixol()`.\nUI:N - The attacker executes the probed instruction in its own process to trigger the XOL copy; no action by any other user or victim is required.\nS:U - The stale instruction executes in the traced process's own user context and the WARN/panic effects stay within the kernel's own authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The traced process — potentially a privileged daemon or setuid binary under a system-wide probe on libc/libssl — executes a stale instruction with its live register state, a control-flow-integrity failure that can branch into or read out that process's memory. The attacker influences what sits in the I-cache at that kernel-provided address.\nI:H - Executing a stale/wrong instruction with the probed process's live registers yields arbitrary stores and control-flow deviation inside that process, and the trailing ebreak may be skipped entirely, letting the PC run past the slot into adjacent slot contents.\nA:H - The probed process is killed via `force_sig(SIGILL)`, and the broken single-step contract hits `WARN_ON_ONCE` in both `arch_uprobe_post_xol()` and `handle_singlestep()`, which is a kernel panic under `panic_on_warn`. The commit reports uprobe selftests randomly blowing up on real hardware."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "arch/riscv/kernel/probes/uprobes.c"
                    ],
                    "versions": [
                        {
                            "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
                            "lessThan": "be6d98766ac952d38241d5a5b213f363afa421c3",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
                            "lessThan": "b6d8d4d01ca8514fa89b05355f296758a91e2297",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
                            "lessThan": "77c956152a3a7c7a18b68f3654f70565b2181d03",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
                            "lessThan": "bcf6d3158c5902d92b6d62335af4422b7bf7c4e2",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
                            "lessThan": "1dbb95a36499374c51b47ee8ae258a8862c20978",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "74784081aac8a0f3636965fc230e2d3b7cc123c6",
                            "lessThan": "7d1d19a11cfbfd8bae1d89cc010b2cc397cd0c48",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "arch/riscv/kernel/probes/uprobes.c"
                    ],
                    "versions": [
                        {
                            "version": "5.12",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.12",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.200",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.163",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.121",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.26",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.14.5",
                            "lessThanOrEqual": "6.14.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.15",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.12",
                                    "versionEndExcluding": "5.15.200"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.12",
                                    "versionEndExcluding": "6.1.163"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.12",
                                    "versionEndExcluding": "6.6.121"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.12",
                                    "versionEndExcluding": "6.12.26"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.12",
                                    "versionEndExcluding": "6.14.5"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.12",
                                    "versionEndExcluding": "6.15"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/be6d98766ac952d38241d5a5b213f363afa421c3"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b6d8d4d01ca8514fa89b05355f296758a91e2297"
                },
                {
                    "url": "https://git.kernel.org/stable/c/77c956152a3a7c7a18b68f3654f70565b2181d03"
                },
                {
                    "url": "https://git.kernel.org/stable/c/bcf6d3158c5902d92b6d62335af4422b7bf7c4e2"
                },
                {
                    "url": "https://git.kernel.org/stable/c/1dbb95a36499374c51b47ee8ae258a8862c20978"
                },
                {
                    "url": "https://git.kernel.org/stable/c/7d1d19a11cfbfd8bae1d89cc010b2cc397cd0c48"
                }
            ],
            "title": "riscv: uprobes: Add missing fence.i after building the XOL buffer",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}