cbcvebase.
CVE-2022-50008
published 2025-06-18

CVE-2022-50008: In the Linux kernel, the following vulnerability has been resolved: kprobes: don't call disarm_kprobe() for disabled kprobes The assumption in…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.1th percentile
In the Linux kernel, the following vulnerability has been resolved:

kprobes: don't call disarm_kprobe() for disabled kprobes

The assumption in __disable_kprobe() is wrong, and it could try to disarm
an already disarmed kprobe and fire the WARN_ONCE() below. [0] We can
easily reproduce this issue.

1. Write 0 to /sys/kernel/debug/kprobes/enabled.

# echo 0 > /sys/kernel/debug/kprobes/enabled

2. Run execsnoop. At this time, one kprobe is disabled.

# /usr/share/bcc/tools/execsnoop &
[1] 2460
PCOMM PID PPID RET ARGS

# cat /sys/kernel/debug/kprobes/list
ffffffff91345650 r __x64_sys_execve+0x0 [FTRACE]
ffffffff91345650 k __x64_sys_execve+0x0 [DISABLED][FTRACE]

3. Write 1 to /sys/kernel/debug/kprobes/enabled, which changes
kprobes_all_disarmed to false but does not arm the disabled kprobe.

# echo 1 > /sys/kernel/debug/kprobes/enabled

# cat /sys/kernel/debug/kprobes/list
ffffffff91345650 r __x64_sys_execve+0x0 [FTRACE]
ffffffff91345650 k __x64_sys_execve+0x0 [DISABLED][FTRACE]

4. Kill execsnoop, when __disable_kprobe() calls disarm_kprobe() for the
disabled kprobe and hits the WARN_ONCE() in __disarm_kprobe_ftrace().

# fg
/usr/share/bcc/tools/execsnoop
^C

Actually, WARN_ONCE() is fired twice, and __unregister_kprobe_top() misses
some cleanups and leaves the aggregated kprobe in the hash table. Then,
__unregister_trace_kprobe() initialises tk->rp.kp.list and creates an
infinite loop like this.

aggregated kprobe.list -> kprobe.list -.
^ |
'.__.'

In this situation, these commands fall into the infinite loop and result
in RCU stall or soft lockup.

cat /sys/kernel/debug/kprobes/list : show_kprobe_addr() enters into the
infinite loop with RCU.

/usr/share/bcc/tools/execsnoop : warn_kprobe_rereg() holds kprobe_mutex,
and __get_valid_kprobe() is stuck in
the loop.

To avoid the issue, make sure we don't call disarm_kprobe() for disabled
kprobes.

[0]
Failed to disarm kprobe-ftrace at __x64_sys_execve+0x0/0x40 (error -2)
WARNING: CPU: 6 PID: 2460 at kernel/kprobes.c:11

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 69d54b916d83872a0a327778a01af2a096923f59 < 19cd630712e7c13a3dedfc6986a9b983fed6fd9819cd630712e7c13a3dedfc6986a9b983fed6fd98
linuxlinux>= 69d54b916d83872a0a327778a01af2a096923f59 < 6f3c1bc22fc2165461883f506b4d2c3594bd71376f3c1bc22fc2165461883f506b4d2c3594bd7137
linuxlinux>= 69d54b916d83872a0a327778a01af2a096923f59 < fc91d2db55acdaf0c0075b624e572d3520ca3bc3fc91d2db55acdaf0c0075b624e572d3520ca3bc3
linuxlinux>= 69d54b916d83872a0a327778a01af2a096923f59 < b474ff1b20951f1eac75d100a93861e6da2b522bb474ff1b20951f1eac75d100a93861e6da2b522b
linuxlinux>= 69d54b916d83872a0a327778a01af2a096923f59 < 744b0d3080709a172f0408aedabd1cedd24c2ee6744b0d3080709a172f0408aedabd1cedd24c2ee6
linuxlinux>= 69d54b916d83872a0a327778a01af2a096923f59 < 55c7a91527343d2e0b5647cc308c6e04ddd2aa5255c7a91527343d2e0b5647cc308c6e04ddd2aa52
linuxlinux>= 69d54b916d83872a0a327778a01af2a096923f59 < bc3188d8a3b8c08c306a4c851ddb2c92ba4599cabc3188d8a3b8c08c306a4c851ddb2c92ba4599ca
linuxlinux>= 69d54b916d83872a0a327778a01af2a096923f59 < 9c80e79906b4ca440d09e7f116609262bb7479099c80e79906b4ca440d09e7f116609262bb747909
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.148-15.10.148-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 4.0 < 4.9.3274.9.327
linuxlinux_kernel>= 4.10 < 4.14.2924.14.292
linuxlinux_kernel>= 4.15 < 4.19.2574.19.257
linuxlinux_kernel>= 4.20 < 5.4.2125.4.212
linuxlinux_kernel>= 5.11 < 5.15.655.15.65
linuxlinux_kernel>= 5.16 < 5.19.65.19.6
linuxlinux_kernel>= 5.5 < 5.10.1415.10.141

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.