CVE-2025-40319
EPSS 0.06%發布日:2025/12/8修改日:2026/4/28
描述
In the Linux kernel, the following vulnerability has been resolved: bpf: Sync pending IRQ work before freeing ring buffer Fix a race where irq_work can be queued in bpf_ringbuf_commit() but the ring buffer is freed before the work executes. In the syzbot reproducer, a BPF program attached to sched_switch triggers bpf_ringbuf_commit(), queuing an irq_work. If the ring buffer is freed before this work executes, the irq_work thread may accesses freed memory. Calling `irq_work_sync(&rb->work)` ensures that all pending irq_work complete before freeing the buffer.
受影響套件(2)
- Debian/linuxfrom 0, < 5.10.247-1
- Debian/linux-6.1from 0, < 6.1.159-1~deb11u1