CVE-2025-40021

Description

A missing security check was found in the Linux kernel's tracing subsystem in the dynamic events interface on tracefs. A local user can bypass kernel lockdown restrictions by using the dynamic_events interface to create kprobes or uprobes, since this interface lacks the lockdown validation present in the equivalent kprobe_events and uprobe_events interfaces. This allows unauthorized modification of kernel tracing state on systems where lockdown should prevent such operations.

Statement

Kernel lockdown is a security feature that restricts certain operations when the system is in a secured state, such as when Secure Boot is enabled. The kprobe_events and uprobe_events tracefs interfaces properly check lockdown status before allowing probe creation, but the dynamic_events interface provides equivalent functionality without this check. An attacker on a lockdown-enabled system could use dynamic_events to attach probes that would otherwise be blocked, potentially enabling kernel inspection or tampering that lockdown was meant to prevent. Exploitation requires local access to tracefs, which typically requires root or membership in the tracing group.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score4.4N/AN/A
Attack VectorLocalN/AN/A
Attack ComplexityLowN/AN/A
Privileges RequiredHighN/AN/A
User InteractionNoneN/AN/A
ScopeUnchangedN/AN/A
ConfidentialityNoneN/AN/A
Integrity ImpactNoneN/AN/A
Availability ImpactHighN/AN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Frequently Asked Questions

Want to get errata notifications? Sign up here.