CVE-2025-39683: tracing: Limit access to parser->buffer when trace_get_user failed
In the Linux kernel, the following vulnerability has been resolved:
tracing: Limit access to parser->buffer when trace_get_user failed
When the length of the string written to set_ftrace_filter exceeds
FTRACE_BUFF_MAX, the following KASAN alarm will be triggered:
BUG: KASAN: slab-out-of-bounds in strsep+0x18c/0x1b0
Read of size 1 at addr ffff0000d00bd5ba by task ash/165
CPU: 1 UID: 0 PID: 165 Comm: ash Not tainted 6.16.0-g6bcdbd62bd56-dirty
Hardware name: linux,dummy-virt (DT)
Call trace:
show_stack+0x34/0x50 (C)
dump_stack_lvl+0xa0/0x158
print_address_description.constprop.0+0x88/0x398
print_report+0xb0/0x280
kasan_report+0xa4/0xf0
__asan_report_load1_noabort+0x20/0x30
strsep+0x18c/0x1b0
ftrace_process_regex.isra.0+0x100/0x2d8
ftrace_regex_release+0x484/0x618
__fput+0x364/0xa58
____fput+0x28/0x40
task_work_run+0x154/0x278
do_notify_resume+0x1f0/0x220
el0_svc+0xec/0xf0
el0t_64_sync_handler+0xa0/0xe8
el0t_64_sync+0x1ac/0x1b0
The reason is that trace_get_user will fail when processing a string
longer than FTRACE_BUFF_MAX, but not set the end of parser->buffer to 0.
Then an OOB access will be triggered in ftrace_regex_release->
ftrace_process_regex->strsep->strpbrk. We can solve this problem by
limiting access to parser->buffer when trace_get_user failed.
Security readout for executives and security teams
Plain-English summary
A Linux kernel tracing flaw can cause the kernel to read beyond an allocated buffer when an overly long tracing filter is submitted. The attack is local, not directly network-reachable. The 7.8 score indicates potentially serious consequences, but the supplied evidence demonstrates an out-of-bounds read, not a working privilege-escalation exploit.
Executive priority
Treat this as high-priority kernel maintenance, especially where less-trusted local users or processes can access tracing. Accelerate vendor updates, but current evidence does not support describing it as an actively exploited remote emergency.
Technical view
When trace_get_user rejects input longer than FTRACE_BUFF_MAX, parser->buffer is not terminated. ftrace_regex_release later processes it through ftrace_process_regex and strsep/strpbrk, causing a KASAN-observed one-byte slab out-of-bounds read. Upstream fixes limit buffer access following the failure. The supplied CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Likely exposure
Exposure requires vulnerable Linux tracing code and a local actor able to write an oversized string to set_ftrace_filter. The CVSS vector specifies low privileges, but the supplied crash involved UID 0; practical reach therefore depends on tracing permissions and configuration. The bundle's version mapping is ambiguous, so confirm exposure against distributor guidance and applicable fix commits.
Exploitation context
KEV is false, and the bundle provides no evidence of active exploitation or a public exploit. It documents a KASAN-detected slab out-of-bounds read during cleanup after an oversized filter write. Practical exploitation beyond the demonstrated memory-safety violation is not established by the supplied sources.
Researcher notes
The failure path is central: oversized input makes trace_get_user fail without terminating parser->buffer, and release-time parsing reads beyond the slab. KASAN confirms an out-of-bounds read. No CWE is supplied, and the sources do not establish code execution, privilege escalation, or reliable denial of service. Resolve version applicability per distribution branch.
Mitigation direction
Apply a vendor-provided kernel update containing the applicable stable fix for your kernel branch.
Consult the Linux distributor or device vendor for corrected packages and branch-specific guidance.
Prioritize systems where less-trusted local users or processes can access kernel tracing controls.
Validation and detection
Inventory running kernel builds and identify systems potentially matching the bundle's affected entries.
Compare each build with its distributor advisory and the applicable upstream stable fix commit.
Review who can access set_ftrace_filter and other relevant tracing controls.
After updating, confirm the corrected kernel build is running using vendor-supported verification procedures.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-39683 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
2ADP providers
12Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.