CVE-2025-40021
Description
A missing security check was found in the Linux kernel's tracing subsystem in the dynamic events interface on tracefs. A local user can bypass kernel lockdown restrictions by using the dynamic_events interface to create kprobes or uprobes, since this interface lacks the lockdown validation present in the equivalent kprobe_events and uprobe_events interfaces. This allows unauthorized modification of kernel tracing state on systems where lockdown should prevent such operations.
Statement
Kernel lockdown is a security feature that restricts certain operations when the system is in a secured state, such as when Secure Boot is enabled. The kprobe_events and uprobe_events tracefs interfaces properly check lockdown status before allowing probe creation, but the dynamic_events interface provides equivalent functionality without this check. An attacker on a lockdown-enabled system could use dynamic_events to attach probes that would otherwise be blocked, potentially enabling kernel inspection or tampering that lockdown was meant to prevent. Exploitation requires local access to tracefs, which typically requires root or membership in the tracing group.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 4.4 | N/A | N/A |
| Attack Vector | Local | N/A | N/A |
| Attack Complexity | Low | N/A | N/A |
| Privileges Required | High | N/A | N/A |
| User Interaction | None | N/A | N/A |
| Scope | Unchanged | N/A | N/A |
| Confidentiality | None | N/A | N/A |
| Integrity Impact | None | N/A | N/A |
| Availability Impact | High | N/A | N/A |
Vector
Red Hat: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.