CVE-2025-38322
Published: Jul 10, 2025
Modified: May 23, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix crash in icl_update_topdown_event() The perf_fuzzer found a hard-lockup crash on a RaptorLake machine: Oops: general protection fault, maybe for address 0xffff89aeceab400: 0000 CPU: 23 UID: 0 PID: 0 Comm: swapper/23 Tainted: [W]=WARN Hardware name: Dell Inc. Precision 9660/0VJ762 RIP: 0010:native_read_pmc+0x7/0x40 Code: cc e8 8d a9 01 00 48 89 03 5b cd cc cc cc cc 0f 1f ... RSP: 000:fffb03100273de8 EFLAGS: 00010046 .... Call Trace: <TASK> icl_update_topdown_event+0x165/0x190 ? ktime_get+0x38/0xd0 intel_pmu_read_event+0xf9/0x210 __perf_event_read+0xf9/0x210 CPUs 16-23 are E-core CPUs that don't support the perf metrics feature. The icl_update_topdown_event() should not be invoked on these CPUs. It's a regression of commit: f9bdf1f95339 ("perf/x86/intel: Avoid disable PMU if !cpuc->enabled in sample read") The bug introduced by that commit is that the is_topdown_event() function is mistakenly used to replace the is_topdown_count() call to check if the topdown functions for the perf metrics feature should be invoked. Fix it.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 781b2db0eb7731fbde510c268b7ccc62959c3feb - < 702ea6028032d6c1fe96c2d4762a3575e3654819affected e7f6922c8a5b41522a8329ea6bbf815993b2dd28 - < 79e2dd573116d3338507c311460da9669095c94daffected 3a8bec6583e5239de3bd597ab382dc6c2b0c29a1 - < e97c45c770f5e56c784a46c2a96ab968d26b97d9affected f9bdf1f953392c9edd69a7f884f78c0390127029 - < a85cc69acdcb05f8cd226b8ea0778b8e2e887e6faffected f9bdf1f953392c9edd69a7f884f78c0390127029 - < b0823d5fbacb1c551d793cbfe7af24e0d1fa45ed+7 more versions |
Linux | Linux | affected 6.15unaffected 0 - < 6.15unaffected 6.1.149 - <= 6.1.*unaffected 6.6.101 - <= 6.6.*unaffected 6.12.49 - <= 6.12.*+2 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now