cbcvebase.
CVE-2025-37845
published 2025-05-09

CVE-2025-37845: In the Linux kernel, the following vulnerability has been resolved: tracing: fprobe events: Fix possible UAF on modules Commit ac91052f0ae5 ("tracing…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
18.0th percentile
In the Linux kernel, the following vulnerability has been resolved: tracing: fprobe events: Fix possible UAF on modules Commit ac91052f0ae5 ("tracing: tprobe-events: Fix leakage of module refcount") moved try_module_get() from __find_tracepoint_module_cb() to find_tracepoint() caller, but that introduced a possible UAF because the module can be unloaded before try_module_get(). In this case, the module object should be freed too. Thus, try_module_get() does not only fail but may access to the freed object. To avoid that, try_module_get() in __find_tracepoint_module_cb() again.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.25-1 (forky)linux 6.12.25-1 (forky)
linuxlinux
linuxlinux>= 6.12.21 < 6.12.246.12.24
linuxlinux>= 6.13.9 < 6.13.126.13.12
linuxlinux>= 71c9cf87776eaa556fc0a0a060df94200e1f521c < 868df4eb784c3ccc7e4340a9ea993cbbedca167e868df4eb784c3ccc7e4340a9ea993cbbedca167e
linuxlinux>= 9db2b8cf4ea07b579db588e0353d5680f5d1f071 < a27d2de2472b1cc7d582ab405d1d5832a80481dea27d2de2472b1cc7d582ab405d1d5832a80481de
linuxlinux>= ac91052f0ae5be9e46211ba92cc31c0e3b0a933a < 626f01f4d26e8cf92e69c1df53036153c8e98a20626f01f4d26e8cf92e69c1df53036153c8e98a20
linuxlinux>= ac91052f0ae5be9e46211ba92cc31c0e3b0a933a < dd941507a9486252d6fcf11814387666792020f3dd941507a9486252d6fcf11814387666792020f3
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.12.21 < 6.12.246.12.24
linuxlinux_kernel>= 6.13.9 < 6.13.126.13.12
linuxlinux_kernel>= 6.14.1 < 6.14.36.14.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.