CVE-2025-22048
published 2025-04-16CVE-2025-22048: In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Don't override subprog's return value The verifier test `calls: div by 0 in…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Don't override subprog's return value
The verifier test `calls: div by 0 in subprog` triggers a panic at the
ld.bu instruction. The ld.bu insn is trying to load byte from memory
address returned by the subprog. The subprog actually set the correct
address at the a5 register (dedicated register for BPF return values).
But at commit 73c359d1d356 ("LoongArch: BPF: Sign-extend return values")
we also sign extended a5 to the a0 register (return value in LoongArch).
For function call insn, we later propagate the a0 register back to a5
register. This is right for native calls but wrong for bpf2bpf calls
which expect zero-extended return value in a5 register. So only move a0
to a5 for native calls (i.e. non-BPF_PSEUDO_CALL).
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.12.25-1 (forky) | linux 6.12.25-1 (forky) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 0c8d50501bc13cacecc19caaddc10db372592a39 < 7df2696256a034405d3c5a71b3a4c54725de4404 | 7df2696256a034405d3c5a71b3a4c54725de4404 |
| linux | linux | >= 6.1.120 < 6.2 | 6.2 |
| linux | linux | >= 6.11.11 < 6.12 | 6.12 |
| linux | linux | >= 6.12.2 < 6.12.23 | 6.12.23 |
| linux | linux | >= 6.6.64 < 6.6.87 | 6.6.87 |
| linux | linux | >= 73c359d1d356cf10236ccd358bd55edab33e9424 < 780628a780b622759d9e5adc76d15432144da1a3 | 780628a780b622759d9e5adc76d15432144da1a3 |
| linux | linux | >= 73c359d1d356cf10236ccd358bd55edab33e9424 < 996e90ab446641553e8e21707b38b9709605e0e0 | 996e90ab446641553e8e21707b38b9709605e0e0 |
| linux | linux | >= 73c359d1d356cf10236ccd358bd55edab33e9424 < 60f3caff1492e5b8616b9578c4bedb5c0a88ed14 | 60f3caff1492e5b8616b9578c4bedb5c0a88ed14 |
| linux | linux | >= d5d83242a1d778ceb6d8b07c6b491cf7483ca112 < 223d565d8892481684091cfbaf3466f2b0e289d3 | 223d565d8892481684091cfbaf3466f2b0e289d3 |
| linux | linux_kernel | >= 0 < 6.12.25-1 | 6.12.25-1 |
| linux | linux_kernel | >= 0 < 6.12.25-1 | 6.12.25-1 |
| linux | linux_kernel | >= 6.1.120 < 6.2 | 6.2 |
| linux | linux_kernel | >= 6.11.11 < 6.12 | 6.12 |
| linux | linux_kernel | >= 6.12.2 < 6.12.23 | 6.12.23 |
| linux | linux_kernel | >= 6.13 < 6.13.11 | 6.13.11 |
| linux | linux_kernel | >= 6.14 < 6.14.2 | 6.14.2 |
| linux | linux_kernel | >= 6.6.64 < 6.6.87 | 6.6.87 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-22048: In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Don't override subprog's return value The verifier test `calls: di
osv·2025-04-16·CVSS 5.5
CVE-2025-22048 [MEDIUM] CVE-2025-22048: In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Don't override subprog's return value The verifier test `calls: di
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Don't override subprog's return value The verifier test `calls: div by 0 in subprog` triggers a panic at the ld.bu instruction. The ld.bu insn is trying to load byte from memory address returned by the subprog. The subprog actually set the correct address at the a5 register (dedicated register for BPF return values). But at commit 73c359d1d356 ("LoongArch: BPF: Sign-extend return values") we also sign extended a5 to the a0 register (return value in LoongArch). For function call insn, we later propagate the a0 register back to a5 register. This is right for native calls but wrong for bpf2bpf calls which expect zero-extended return value in a5 register. So only move a0 to a5 for native calls (i.e. non-BPF_PSE
GHSA
GHSA-4vfw-gvwq-xw7v: In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Don't override subprog's return value
The verifier test `calls:
ghsa_unreviewed·2025-04-16
CVE-2025-22048 [MEDIUM] GHSA-4vfw-gvwq-xw7v: In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Don't override subprog's return value
The verifier test `calls:
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Don't override subprog's return value
The verifier test `calls: div by 0 in subprog` triggers a panic at the
ld.bu instruction. The ld.bu insn is trying to load byte from memory
address returned by the subprog. The subprog actually set the correct
address at the a5 register (dedicated register for BPF return values).
But at commit 73c359d1d356 ("LoongArch: BPF: Sign-extend return values")
we also sign extended a5 to the a0 register (return value in LoongArch).
For function call insn, we later propagate the a0 register back to a5
register. This is right for native calls but wrong for bpf2bpf calls
which expect zero-extended return value in a5 register. So only move a0
to a5 for native calls (i.e. non-BPF_P
Red Hat
kernel: LoongArch: BPF: Don't override subprog's return value
vendor_redhat·2025-04-16·CVSS 5.5
CVE-2025-22048 [MEDIUM] kernel: LoongArch: BPF: Don't override subprog's return value
kernel: LoongArch: BPF: Don't override subprog's return value
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Don't override subprog's return value
The verifier test `calls: div by 0 in subprog` triggers a panic at the
ld.bu instruction. The ld.bu insn is trying to load byte from memory
address returned by the subprog. The subprog actually set the correct
address at the a5 register (dedicated register for BPF return values).
But at commit 73c359d1d356 ("LoongArch: BPF: Sign-extend return values")
we also sign extended a5 to the a0 register (return value in LoongArch).
For function call insn, we later propagate the a0 register back to a5
register. This is right for native calls but wrong for bpf2bpf calls
which expect zero-extended return value in a5 reg
Debian
CVE-2025-22048: linux - In the Linux kernel, the following vulnerability has been resolved: LoongArch: ...
vendor_debian·2025·CVSS 5.5
CVE-2025-22048 [MEDIUM] CVE-2025-22048: linux - In the Linux kernel, the following vulnerability has been resolved: LoongArch: ...
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Don't override subprog's return value The verifier test `calls: div by 0 in subprog` triggers a panic at the ld.bu instruction. The ld.bu insn is trying to load byte from memory address returned by the subprog. The subprog actually set the correct address at the a5 register (dedicated register for BPF return values). But at commit 73c359d1d356 ("LoongArch: BPF: Sign-extend return values") we also sign extended a5 to the a0 register (return value in LoongArch). For function call insn, we later propagate the a0 register back to a5 register. This is right for native calls but wrong for bpf2bpf calls which expect zero-extended return value in a5 register. So only move a0 to a5 for native calls (i.e. non-BPF_PSE
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/223d565d8892481684091cfbaf3466f2b0e289d3https://git.kernel.org/stable/c/60f3caff1492e5b8616b9578c4bedb5c0a88ed14https://git.kernel.org/stable/c/780628a780b622759d9e5adc76d15432144da1a3https://git.kernel.org/stable/c/7df2696256a034405d3c5a71b3a4c54725de4404https://git.kernel.org/stable/c/996e90ab446641553e8e21707b38b9709605e0e0
2025-04-16
Published