Answer in brief
CVE-2025-38424 records a Unknown severity vulnerability in perf: Fix sample vs do_exit(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-38424 records a Unknown severity vulnerability in perf: Fix sample vs do_exit(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <7b8f3c72175c6a63a95cf2e219f8b78e2baad34e || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <507c9a595bad3abd107c6a8857d7fd125d89f386 || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <a9f6aab7910a0ef2895797f15c947f6d1053160f || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <975ffddfa2e19823c719459d2364fcaa17673964 || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <2ee6044a693735396bb47eeaba1ac3ae26c1c99b || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <456019adaa2f5366b89c868dea9b483179bece54 || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <7311970d07c4606362081250da95f2c7901fc0db || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <4f6fc782128355931527cefe3eb45338abd8ab39 | 7b8f3c72175c6a63a95cf2e219f8b78e2baad34e, 507c9a595bad3abd107c6a8857d7fd125d89f386, a9f6aab7910a0ef2895797f15c947f6d1053160f, 975ffddfa2e19823c719459d2364fcaa17673964, 2ee6044a693735396bb47eeaba1ac3ae26c1c99b, 456019adaa2f5366b89c868dea9b483179bece54, 7311970d07c4606362081250da95f2c7901fc0db, 4f6fc782128355931527cefe3eb45338abd8ab39 |
| Linux/Linuxgeneric | 3.7 | Not reported |
Published upstream
Jul 25, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: perf: Fix sample vs do_exit() Baisheng Gao reported an ARM64 crash, which Mark decoded as being a synchronous external abort -- most likely due to trying to access MMIO in bad ways. The crash further shows perf trying to do a user stack sample while in exit_mmap()'s tlb_finish_mmu() -- i.e. while tearing down the address space it is trying to access. It turns out that we stop perf after we tear down the userspace mm; a receipie for disaster, since perf likes to access userspace for various reasons. Flip this order by moving up where we stop perf in do_exit(). Additionally, harden PERF_SAMPLE_CALLCHAIN and PERF_SAMPLE_STACK_USER to abort when the current task does not have an mm (exit_mm() makes sure to set current->mm = NULL; before commencing with the actual teardown). Such that CPU wide events don't trip on this same problem.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <7b8f3c72175c6a63a95cf2e219f8b78e2baad34e || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <507c9a595bad3abd107c6a8857d7fd125d89f386 || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <a9f6aab7910a0ef2895797f15c947f6d1053160f || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <975ffddfa2e19823c719459d2364fcaa17673964 || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <2ee6044a693735396bb47eeaba1ac3ae26c1c99b || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <456019adaa2f5366b89c868dea9b483179bece54 || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <7311970d07c4606362081250da95f2c7901fc0db || >=c5ebcedb566ef17bda7b02686e0d658a7bb42ee7 <4f6fc782128355931527cefe3eb45338abd8ab39 | 7b8f3c72175c6a63a95cf2e219f8b78e2baad34e, 507c9a595bad3abd107c6a8857d7fd125d89f386, a9f6aab7910a0ef2895797f15c947f6d1053160f, 975ffddfa2e19823c719459d2364fcaa17673964, 2ee6044a693735396bb47eeaba1ac3ae26c1c99b, 456019adaa2f5366b89c868dea9b483179bece54, 7311970d07c4606362081250da95f2c7901fc0db, 4f6fc782128355931527cefe3eb45338abd8ab39 |
| Linux/Linuxgeneric | 3.7 | Not reported |
Published upstream
Jul 25, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: perf: Fix sample vs do_exit() Baisheng Gao reported an ARM64 crash, which Mark decoded as being a synchronous external abort -- most likely due to trying to access MMIO in bad ways. The crash further shows perf trying to do a user stack sample while in exit_mmap()'s tlb_finish_mmu() -- i.e. while tearing down the address space it is trying to access. It turns out that we stop perf after we tear down the userspace mm; a receipie for disaster, since perf likes to access userspace for various reasons. Flip this order by moving up where we stop perf in do_exit(). Additionally, harden PERF_SAMPLE_CALLCHAIN and PERF_SAMPLE_STACK_USER to abort when the current task does not have an mm (exit_mm() makes sure to set current->mm = NULL; before commencing with the actual teardown). Such that CPU wide events don't trip on this same problem.
Quoted source text, attributed separately from HOL analysis.