cbcvebase.
CVE-2025-21889
published 2025-03-27

CVE-2025-21889: In the Linux kernel, the following vulnerability has been resolved: perf/core: Add RCU read lock protection to perf_iterate_ctx() The perf_iterate_ctx()…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.1th percentile
In the Linux kernel, the following vulnerability has been resolved: perf/core: Add RCU read lock protection to perf_iterate_ctx() The perf_iterate_ctx() function performs RCU list traversal but currently lacks RCU read lock protection. This causes lockdep warnings when running perf probe with unshare(1) under CONFIG_PROVE_RCU_LIST=y: WARNING: suspicious RCU usage kernel/events/core.c:8168 RCU-list traversed in non-reader section!! Call Trace: lockdep_rcu_suspicious ? perf_event_addr_filters_apply perf_iterate_ctx perf_event_exec begin_new_exec ? load_elf_phdrs load_elf_binary ? lock_acquire ? find_held_lock ? bprm_execve bprm_execve do_execveat_common.isra.0 __x64_sys_execve do_syscall_64 entry_SYSCALL_64_after_hwframe This protection was previously present but was removed in commit bd2756811766 ("perf: Rewrite core context handling"). Add back the necessary rcu_read_lock()/rcu_read_unlock() pair around perf_iterate_ctx() call in perf_event_exec(). [ mingo: Use scoped_guard() as suggested by Peter ]

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.19-1 (forky)linux 6.12.19-1 (forky)
linuxlinux
linuxlinux>= bd27568117664b8b3e259721393df420ed51f57b < f390c2eea571945f357a2d3b9fcb1c015767132ef390c2eea571945f357a2d3b9fcb1c015767132e
linuxlinux>= bd27568117664b8b3e259721393df420ed51f57b < a2475ccad6120546ea45dbcd6cd1f74dc565ef6ba2475ccad6120546ea45dbcd6cd1f74dc565ef6b
linuxlinux>= bd27568117664b8b3e259721393df420ed51f57b < dd536566dda9a551fc2a2acfab5313a5bb13ed02dd536566dda9a551fc2a2acfab5313a5bb13ed02
linuxlinux>= bd27568117664b8b3e259721393df420ed51f57b < 0fe8813baf4b2e865d3b2c735ce1a15b86002c740fe8813baf4b2e865d3b2c735ce1a15b86002c74
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 6.13 < 6.13.66.13.6
linuxlinux_kernel>= 6.2 < 6.6.816.6.81
linuxlinux_kernel>= 6.7 < 6.12.186.12.18

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.