CVE-2022-50008
published 2025-06-18CVE-2022-50008: In the Linux kernel, the following vulnerability has been resolved: kprobes: don't call disarm_kprobe() for disabled kprobes The assumption in…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.1th percentile
In the Linux kernel, the following vulnerability has been resolved: kprobes: don't call disarm_kprobe() for disabled kprobes The assumption in __disable_kprobe() is wrong, and it could try to disarm an already disarmed kprobe and fire the WARN_ONCE() below. [0] We can easily reproduce this issue. 1. Write 0 to /sys/kernel/debug/kprobes/enabled. # echo 0 > /sys/kernel/debug/kprobes/enabled 2. Run execsnoop. At this time, one kprobe is disabled. # /usr/share/bcc/tools/execsnoop & [1] 2460 PCOMM PID PPID RET ARGS # cat /sys/kernel/debug/kprobes/list ffffffff91345650 r __x64_sys_execve+0x0 [FTRACE] ffffffff91345650 k __x64_sys_execve+0x0 [DISABLED][FTRACE] 3. Write 1 to /sys/kernel/debug/kprobes/enabled, which changes kprobes_all_disarmed to false but does not arm the disabled kprobe. # echo 1 > /sys/kernel/debug/kprobes/enabled # cat /sys/kernel/debug/kprobes/list ffffffff91345650 r __x64_sys_execve+0x0 [FTRACE] ffffffff91345650 k __x64_sys_execve+0x0 [DISABLED][FTRACE] 4. Kill execsnoop, when __disable_kprobe() calls disarm_kprobe() for the disabled kprobe and hits the WARN_ONCE() in __disarm_kprobe_ftrace(). # fg /usr/share/bcc/tools/execsnoop ^C Actually, WARN_ONCE() is fired twice, and __unregister_kprobe_top() misses some cleanups and leaves the aggregated kprobe in the hash table. Then, __unregister_trace_kprobe() initialises tk->rp.kp.list and creates an infinite loop like this. aggregated kprobe.list -> kprobe.list -. ^ | '.__.' In this situation, these commands fall into the infinite loop and result in RCU stall or soft lockup. cat /sys/kernel/debug/kprobes/list : show_kprobe_addr() enters into the infinite loop with RCU. /usr/share/bcc/tools/execsnoop : warn_kprobe_rereg() holds kprobe_mutex, and __get_valid_kprobe() is stuck in the loop. To avoid the issue, make sure we don't call disarm_kprobe() for disabled kprobes. [0] Failed to disarm kprobe-ftrace at __x64_sys_execve+0x0/0x40 (error -2) WARNING: CPU: 6 PID: 2460 at kernel/kprobes.c:11
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 69d54b916d83872a0a327778a01af2a096923f59 < 19cd630712e7c13a3dedfc6986a9b983fed6fd98 | 19cd630712e7c13a3dedfc6986a9b983fed6fd98 |
| linux | linux | >= 69d54b916d83872a0a327778a01af2a096923f59 < 6f3c1bc22fc2165461883f506b4d2c3594bd7137 | 6f3c1bc22fc2165461883f506b4d2c3594bd7137 |
| linux | linux | >= 69d54b916d83872a0a327778a01af2a096923f59 < fc91d2db55acdaf0c0075b624e572d3520ca3bc3 | fc91d2db55acdaf0c0075b624e572d3520ca3bc3 |
| linux | linux | >= 69d54b916d83872a0a327778a01af2a096923f59 < b474ff1b20951f1eac75d100a93861e6da2b522b | b474ff1b20951f1eac75d100a93861e6da2b522b |
| linux | linux | >= 69d54b916d83872a0a327778a01af2a096923f59 < 744b0d3080709a172f0408aedabd1cedd24c2ee6 | 744b0d3080709a172f0408aedabd1cedd24c2ee6 |
| linux | linux | >= 69d54b916d83872a0a327778a01af2a096923f59 < 55c7a91527343d2e0b5647cc308c6e04ddd2aa52 | 55c7a91527343d2e0b5647cc308c6e04ddd2aa52 |
| linux | linux | >= 69d54b916d83872a0a327778a01af2a096923f59 < bc3188d8a3b8c08c306a4c851ddb2c92ba4599ca | bc3188d8a3b8c08c306a4c851ddb2c92ba4599ca |
| linux | linux | >= 69d54b916d83872a0a327778a01af2a096923f59 < 9c80e79906b4ca440d09e7f116609262bb747909 | 9c80e79906b4ca440d09e7f116609262bb747909 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.148-1 | 5.10.148-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 4.0 < 4.9.327 | 4.9.327 |
| linux | linux_kernel | >= 4.10 < 4.14.292 | 4.14.292 |
| linux | linux_kernel | >= 4.15 < 4.19.257 | 4.19.257 |
| linux | linux_kernel | >= 4.20 < 5.4.212 | 5.4.212 |
| linux | linux_kernel | >= 5.11 < 5.15.65 | 5.15.65 |
| linux | linux_kernel | >= 5.16 < 5.19.6 | 5.19.6 |
| linux | linux_kernel | >= 5.5 < 5.10.141 | 5.10.141 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q44m-58pc-8rr7: In the Linux kernel, the following vulnerability has been resolved:
kprobes: don't call disarm_kprobe() for disabled kprobes
The assumption in __dis
ghsa_unreviewed·2025-06-18
CVE-2022-50008 [MEDIUM] CWE-835 GHSA-q44m-58pc-8rr7: In the Linux kernel, the following vulnerability has been resolved:
kprobes: don't call disarm_kprobe() for disabled kprobes
The assumption in __dis
In the Linux kernel, the following vulnerability has been resolved:
kprobes: don't call disarm_kprobe() for disabled kprobes
The assumption in __disable_kprobe() is wrong, and it could try to disarm
an already disarmed kprobe and fire the WARN_ONCE() below. [0] We can
easily reproduce this issue.
1. Write 0 to /sys/kernel/debug/kprobes/enabled.
# echo 0 > /sys/kernel/debug/kprobes/enabled
2. Run execsnoop. At this time, one kprobe is disabled.
# /usr/share/bcc/tools/execsnoop &
[1] 2460
PCOMM PID PPID RET ARGS
# cat /sys/kernel/debug/kprobes/list
ffffffff91345650 r __x64_sys_execve+0x0 [FTRACE]
ffffffff91345650 k __x64_sys_execve+0x0 [DISABLED][FTRACE]
3. Write 1 to /sys/kernel/debug/kprobes/enabled, which changes
kprobes_all_disarmed to false but does not arm the disabled kprobe.
OSV
CVE-2022-50008: In the Linux kernel, the following vulnerability has been resolved: kprobes: don't call disarm_kprobe() for disabled kprobes The assumption in __disab
osv·2025-06-18·CVSS 5.5
CVE-2022-50008 [MEDIUM] CVE-2022-50008: In the Linux kernel, the following vulnerability has been resolved: kprobes: don't call disarm_kprobe() for disabled kprobes The assumption in __disab
In the Linux kernel, the following vulnerability has been resolved: kprobes: don't call disarm_kprobe() for disabled kprobes The assumption in __disable_kprobe() is wrong, and it could try to disarm an already disarmed kprobe and fire the WARN_ONCE() below. [0] We can easily reproduce this issue. 1. Write 0 to /sys/kernel/debug/kprobes/enabled. # echo 0 > /sys/kernel/debug/kprobes/enabled 2. Run execsnoop. At this time, one kprobe is disabled. # /usr/share/bcc/tools/execsnoop & [1] 2460 PCOMM PID PPID RET ARGS # cat /sys/kernel/debug/kprobes/list ffffffff91345650 r __x64_sys_execve+0x0 [FTRACE] ffffffff91345650 k __x64_sys_execve+0x0 [DISABLED][FTRACE] 3. Write 1 to /sys/kernel/debug/kprobes/enabled, which changes kprobes_all_disarmed to false but does not arm the disabled kprobe. # echo 1
Red Hat
kernel: kprobes: don't call disarm_kprobe() for disabled kprobes
vendor_redhat·2025-06-18·CVSS 5.5
CVE-2022-50008 [MEDIUM] CWE-20 kernel: kprobes: don't call disarm_kprobe() for disabled kprobes
kernel: kprobes: don't call disarm_kprobe() for disabled kprobes
In the Linux kernel, the following vulnerability has been resolved:
kprobes: don't call disarm_kprobe() for disabled kprobes
The assumption in __disable_kprobe() is wrong, and it could try to disarm
an already disarmed kprobe and fire the WARN_ONCE() below. [0] We can
easily reproduce this issue.
1. Write 0 to /sys/kernel/debug/kprobes/enabled.
# echo 0 > /sys/kernel/debug/kprobes/enabled
2. Run execsnoop. At this time, one kprobe is disabled.
# /usr/share/bcc/tools/execsnoop &
[1] 2460
PCOMM PID PPID RET ARGS
# cat /sys/kernel/debug/kprobes/list
ffffffff91345650 r __x64_sys_execve+0x0 [FTRACE]
ffffffff91345650 k __x64_sys_execve+0x0 [DISABLED][FTRACE]
3. Write 1 to /sys/kernel/debug/kprobes/enabled, which changes
kprobes_al
Debian
CVE-2022-50008: linux - In the Linux kernel, the following vulnerability has been resolved: kprobes: do...
vendor_debian·2022·CVSS 5.5
CVE-2022-50008 [MEDIUM] CVE-2022-50008: linux - In the Linux kernel, the following vulnerability has been resolved: kprobes: do...
In the Linux kernel, the following vulnerability has been resolved: kprobes: don't call disarm_kprobe() for disabled kprobes The assumption in __disable_kprobe() is wrong, and it could try to disarm an already disarmed kprobe and fire the WARN_ONCE() below. [0] We can easily reproduce this issue. 1. Write 0 to /sys/kernel/debug/kprobes/enabled. # echo 0 > /sys/kernel/debug/kprobes/enabled 2. Run execsnoop. At this time, one kprobe is disabled. # /usr/share/bcc/tools/execsnoop & [1] 2460 PCOMM PID PPID RET ARGS # cat /sys/kernel/debug/kprobes/list ffffffff91345650 r __x64_sys_execve+0x0 [FTRACE] ffffffff91345650 k __x64_sys_execve+0x0 [DISABLED][FTRACE] 3. Write 1 to /sys/kernel/debug/kprobes/enabled, which changes kprobes_all_disarmed to false but does not arm the disabled kprobe. # echo 1
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/19cd630712e7c13a3dedfc6986a9b983fed6fd98https://git.kernel.org/stable/c/55c7a91527343d2e0b5647cc308c6e04ddd2aa52https://git.kernel.org/stable/c/6f3c1bc22fc2165461883f506b4d2c3594bd7137https://git.kernel.org/stable/c/744b0d3080709a172f0408aedabd1cedd24c2ee6https://git.kernel.org/stable/c/9c80e79906b4ca440d09e7f116609262bb747909https://git.kernel.org/stable/c/b474ff1b20951f1eac75d100a93861e6da2b522bhttps://git.kernel.org/stable/c/bc3188d8a3b8c08c306a4c851ddb2c92ba4599cahttps://git.kernel.org/stable/c/fc91d2db55acdaf0c0075b624e572d3520ca3bc3
2025-06-18
Published