CVE-2025-40151: LoongArch: BPF: No support of struct argument in trampoline programs
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: No support of struct argument in trampoline programs
The current implementation does not support struct argument. This causes
a oops when running bpf selftest:
$ ./test_progs -a tracing_struct
Oops[#1]:
CPU -1 Unable to handle kernel paging request at virtual address 0000000000000018, era == 9000000085bef268, ra == 90000000844f3938
rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
rcu: 1-...0: (19 ticks this GP) idle=1094/1/0x4000000000000000 softirq=1380/1382 fqs=801
rcu: (detected by 0, t=5252 jiffies, g=1197, q=52 ncpus=4)
Sending NMI from CPU 0 to CPUs 1:
rcu: rcu_preempt kthread starved for 2495 jiffies! g1197 f0x0 RCU_GP_DOING_FQS(6) ->state=0x0 ->cpu=2
rcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
rcu: RCU grace-period kthread stack dump:
task:rcu_preempt state:I stack:0 pid:15 tgid:15 ppid:2 task_flags:0x208040 flags:0x00000800
Stack : 9000000100423e80 0000000000000402 0000000000000010 90000001003b0680
9000000085d88000 0000000000000000 0000000000000040 9000000087159350
9000000085c2b9b0 0000000000000001 900000008704a000 0000000000000005
00000000ffff355b 00000000ffff355b 0000000000000000 0000000000000004
9000000085d90510 0000000000000000 0000000000000002 7b5d998f8281e86e
00000000ffff355c 7b5d998f8281e86e 000000000000003f 9000000087159350
900000008715bf98 0000000000000005 9000000087036000 900000008704a000
9000000100407c98 90000001003aff80 900000008715c4c0 9000000085c2b9b0
00000000ffff355b 9000000085c33d3c 00000000000000b4 0000000000000000
9000000007002150 00000000ffff355b 9000000084615480 0000000007000002
...
Call Trace:
[<9000000085c2a868>] __schedule+0x410/0x1520
[<9000000085c2b9ac>] schedule+0x34/0x190
[<9000000085c33d38>] schedule_timeout+0x98/0x140
[<90000000845e9120>] rcu_gp_fqs_loop+0x5f8/0x868
[<90000000845ed538>] rcu_gp_kthread+0x260/0x2e0
[<900000008454e8a4>] kthread+0x144/0x238
[<9000000085c26b60>] ret_from_kernel_thread+0x28/0xc8
[<90000000844f20e4>] ret_from_kernel_thread_asm+0xc/0x88
rcu: Stack dump where RCU GP kthread last ran:
Sending NMI from CPU 0 to CPUs 2:
NMI backtrace for cpu 2 skipped: idling at idle_exit+0x0/0x4
Reject it for now.
Security readout for executives and security teams
Plain-English summary
A Linux kernel flaw on LoongArch systems can crash or severely stall the operating system when a BPF tracing trampoline receives an unsupported structure argument. The reported failure includes a kernel paging error, RCU stalls, and possible out-of-memory behavior. This can disrupt affected servers, but the supplied evidence does not demonstrate real-world data theft or modification.
Executive priority
Prioritize LoongArch systems where local users, development workloads, observability agents, or administrators can use BPF tracing. Schedule prompt kernel remediation because successful triggering can destabilize the host. Other CPU architectures are not identified as affected in the supplied evidence.
Technical view
The LoongArch BPF trampoline implementation did not support structure arguments but failed to reject them safely. Exercising this path caused an invalid memory access, followed by RCU starvation and potential OOM conditions. The supplied record assigns CVSS 3.1 score 7.8 with local, low-complexity, low-privilege access. The referenced resolution rejects unsupported structure arguments.
Likely exposure
Exposure is limited to LoongArch systems running an affected Linux kernel and allowing a local user to exercise relevant BPF tracing trampoline functionality. The bundle identifies Linux 6.17-related versions as affected, but its version data is ambiguous. Confirm exact affected and fixed releases through the kernel vendor and referenced commits.
Exploitation context
CISA KEV status is false, and the supplied sources provide no evidence of active exploitation or a public weaponized exploit. The documented trigger occurred during the Linux BPF selftest. The demonstrated impact is kernel instability and denial of service; practical confidentiality or integrity impact is not established by the bundle.
Researcher notes
The root issue is unsupported structure-argument handling in LoongArch BPF trampolines. The record shows a reproducible kernel oops from the tracing_struct selftest and secondary RCU starvation. Researchers should distinguish the demonstrated availability failure from the CVSS vector's broader confidentiality and integrity ratings; the supplied evidence does not establish those outcomes.
Mitigation direction
Update to a vendor-supported kernel release containing the applicable referenced stable fix.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-40151 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
3Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.