LiveActive security incident?Get immediate response
CVE Record

CVE-2025-39683: tracing: Limit access to parser->buffer when trace_get_user failed

In the Linux kernel, the following vulnerability has been resolved: tracing: Limit access to parser->buffer when trace_get_user failed When the length of the string written to set_ftrace_filter exceeds FTRACE_BUFF_MAX, the following KASAN alarm will be triggered: BUG: KASAN: slab-out-of-bounds in strsep+0x18c/0x1b0 Read of size 1 at addr ffff0000d00bd5ba by task ash/165 CPU: 1 UID: 0 PID: 165 Comm: ash Not tainted 6.16.0-g6bcdbd62bd56-dirty Hardware name: linux,dummy-virt (DT) Call trace: show_stack+0x34/0x50 (C) dump_stack_lvl+0xa0/0x158 print_address_description.constprop.0+0x88/0x398 print_report+0xb0/0x280 kasan_report+0xa4/0xf0 __asan_report_load1_noabort+0x20/0x30 strsep+0x18c/0x1b0 ftrace_process_regex.isra.0+0x100/0x2d8 ftrace_regex_release+0x484/0x618 __fput+0x364/0xa58 ____fput+0x28/0x40 task_work_run+0x154/0x278 do_notify_resume+0x1f0/0x220 el0_svc+0xec/0xf0 el0t_64_sync_handler+0xa0/0xe8 el0t_64_sync+0x1ac/0x1b0 The reason is that trace_get_user will fail when processing a string longer than FTRACE_BUFF_MAX, but not set the end of parser->buffer to 0. Then an OOB access will be triggered in ftrace_regex_release-> ftrace_process_regex->strsep->strpbrk. We can solve this problem by limiting access to parser->buffer when trace_get_user failed.

HighCVSS 7.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A Linux kernel tracing flaw can cause the kernel to read beyond an allocated buffer when an overly long tracing filter is submitted. The attack is local, not directly network-reachable. The 7.8 score indicates potentially serious consequences, but the supplied evidence demonstrates an out-of-bounds read, not a working privilege-escalation exploit.

Executive priority

Treat this as high-priority kernel maintenance, especially where less-trusted local users or processes can access tracing. Accelerate vendor updates, but current evidence does not support describing it as an actively exploited remote emergency.

Technical view

When trace_get_user rejects input longer than FTRACE_BUFF_MAX, parser->buffer is not terminated. ftrace_regex_release later processes it through ftrace_process_regex and strsep/strpbrk, causing a KASAN-observed one-byte slab out-of-bounds read. Upstream fixes limit buffer access following the failure. The supplied CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.

Likely exposure

Exposure requires vulnerable Linux tracing code and a local actor able to write an oversized string to set_ftrace_filter. The CVSS vector specifies low privileges, but the supplied crash involved UID 0; practical reach therefore depends on tracing permissions and configuration. The bundle's version mapping is ambiguous, so confirm exposure against distributor guidance and applicable fix commits.

Exploitation context

KEV is false, and the bundle provides no evidence of active exploitation or a public exploit. It documents a KASAN-detected slab out-of-bounds read during cleanup after an oversized filter write. Practical exploitation beyond the demonstrated memory-safety violation is not established by the supplied sources.

Researcher notes

The failure path is central: oversized input makes trace_get_user fail without terminating parser->buffer, and release-time parsing reads beyond the slab. KASAN confirms an out-of-bounds read. No CWE is supplied, and the sources do not establish code execution, privilege escalation, or reliable denial of service. Resolve version applicability per distribution branch.

Mitigation direction

  • Apply a vendor-provided kernel update containing the applicable stable fix for your kernel branch.
  • Consult the Linux distributor or device vendor for corrected packages and branch-specific guidance.
  • Prioritize systems where less-trusted local users or processes can access kernel tracing controls.

Validation and detection

  • Inventory running kernel builds and identify systems potentially matching the bundle's affected entries.
  • Compare each build with its distributor advisory and the applicable upstream stable fix commit.
  • Review who can access set_ftrace_filter and other relevant tracing controls.
  • After updating, confirm the corrected kernel build is running using vendor-supported verification procedures.
Prepared
Confidence
medium
Sources
9

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-39683 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
2ADP providers
12Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.8CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H1.85.9Linux

Vulnerability scoring details

Base CVSS 3.1 score

7.8High
CVSS 3.1 vector shape for CVE-2025-39683Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CVECVE Program Container
siemens-SADPADP container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux634684d79733124f7470b226b0f42aada4426b07, 8c9af478c06bb1ab1422f90d8ecbc53defd44bc3, 8c9af478c06bb1ab1422f90d8ecbc53defd44bc3, 8c9af478c06bb1ab1422f90d8ecbc53defd44bc3, 8c9af478c06bb1ab1422f90d8ecbc53defd44bc3, 8c9af478c06bb1ab1422f90d8ecbc53defd44bc3, 8c9af478c06bb1ab1422f90d8ecbc53defd44bc3, 24cd31752f47699b89b4b3471155c8e599a1a23a, e9cb474de7ff7a970c2a3951c12ec7e3113c0c35, 6ab671191f64b0da7d547e2ad4dc199ca7e5b558, 3d9281a4ac7171c808f9507f0937eb236b353905, 0b641b25870f02e2423e494365fc5243cc1e2759, ffd51dbfd2900e50c71b5c069fe407957e52d61f, cdd107d7f18158d966c2bc136204fe826dac445c, 5.10.36, 4.4.269, 4.9.269, 4.14.233, 4.19.191, 5.4.118, 5.11.20, 5.12.3unaffected
LinuxLinux5.13, 0, 5.10.241, 5.15.190, 6.1.149, 6.6.103, 6.12.44, 6.16.4, 6.17affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.