Answer in brief
CVE-2025-21889 records a Unknown severity vulnerability in perf/core: Add RCU read lock protection to perf_iterate_ctx(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bd27568117664b8b3e259721393df420ed51f57b <f390c2eea571945f357a2d3b9fcb1c015767132e || >=bd27568117664b8b3e259721393df420ed51f57b <a2475ccad6120546ea45dbcd6cd1f74dc565ef6b || >=bd27568117664b8b3e259721393df420ed51f57b <dd536566dda9a551fc2a2acfab5313a5bb13ed02 || >=bd27568117664b8b3e259721393df420ed51f57b <0fe8813baf4b2e865d3b2c735ce1a15b86002c74 | f390c2eea571945f357a2d3b9fcb1c015767132e, a2475ccad6120546ea45dbcd6cd1f74dc565ef6b, dd536566dda9a551fc2a2acfab5313a5bb13ed02, 0fe8813baf4b2e865d3b2c735ce1a15b86002c74 |
| Linux/Linuxgeneric | 6.2 | Not reported |
Published upstream
Mar 27, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: perf/core: Add RCU read lock protection to perf_iterate_ctx() The perf_iterate_ctx() function performs RCU list traversal but currently lacks RCU read lock protection. This causes lockdep warnings when running perf probe with unshare(1) under CONFIG_PROVE_RCU_LIST=y: WARNING: suspicious RCU usage kernel/events/core.c:8168 RCU-list traversed in non-reader section!! Call Trace: lockdep_rcu_suspicious ? perf_event_addr_filters_apply perf_iterate_ctx perf_event_exec begin_new_exec ? load_elf_phdrs load_elf_binary ? lock_acquire ? find_held_lock ? bprm_execve bprm_execve do_execveat_common.isra.0 __x64_sys_execve do_syscall_64 entry_SYSCALL_64_after_hwframe This protection was previously present but was removed in commit bd2756811766 ("perf: Rewrite core context handling"). Add back the necessary rcu_read_lock()/rcu_read_unlock() pair around perf_iterate_ctx() call in perf_event_exec(). [ mingo: Use scoped_guard() as suggested by Peter ]
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-21889 records a Unknown severity vulnerability in perf/core: Add RCU read lock protection to perf_iterate_ctx(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bd27568117664b8b3e259721393df420ed51f57b <f390c2eea571945f357a2d3b9fcb1c015767132e || >=bd27568117664b8b3e259721393df420ed51f57b <a2475ccad6120546ea45dbcd6cd1f74dc565ef6b || >=bd27568117664b8b3e259721393df420ed51f57b <dd536566dda9a551fc2a2acfab5313a5bb13ed02 || >=bd27568117664b8b3e259721393df420ed51f57b <0fe8813baf4b2e865d3b2c735ce1a15b86002c74 | f390c2eea571945f357a2d3b9fcb1c015767132e, a2475ccad6120546ea45dbcd6cd1f74dc565ef6b, dd536566dda9a551fc2a2acfab5313a5bb13ed02, 0fe8813baf4b2e865d3b2c735ce1a15b86002c74 |
| Linux/Linuxgeneric | 6.2 | Not reported |
Published upstream
Mar 27, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: perf/core: Add RCU read lock protection to perf_iterate_ctx() The perf_iterate_ctx() function performs RCU list traversal but currently lacks RCU read lock protection. This causes lockdep warnings when running perf probe with unshare(1) under CONFIG_PROVE_RCU_LIST=y: WARNING: suspicious RCU usage kernel/events/core.c:8168 RCU-list traversed in non-reader section!! Call Trace: lockdep_rcu_suspicious ? perf_event_addr_filters_apply perf_iterate_ctx perf_event_exec begin_new_exec ? load_elf_phdrs load_elf_binary ? lock_acquire ? find_held_lock ? bprm_execve bprm_execve do_execveat_common.isra.0 __x64_sys_execve do_syscall_64 entry_SYSCALL_64_after_hwframe This protection was previously present but was removed in commit bd2756811766 ("perf: Rewrite core context handling"). Add back the necessary rcu_read_lock()/rcu_read_unlock() pair around perf_iterate_ctx() call in perf_event_exec(). [ mingo: Use scoped_guard() as suggested by Peter ]
Quoted source text, attributed separately from HOL analysis.