kprobes: Skip clearing aggrprobe's post_handler in kprobe-on-ftrace case
Published May 1, 2025
7.8
HIGHCVSS 3.1
EPSS 0.22%
Description
In __unregister_kprobe_top(), if the currently unregistered probe has post_handler but other child probes of the aggrprobe do not have post_handler, the post_handler of the aggrprobe is cleared. If this is a ftrace-based probe, there is a problem. In later calls to disarm_kprobe(), we will use kprobe_ftrace_ops because post_handler is NULL. But we're armed with kprobe_ipmodify_ops. This triggers a WARN in __disarm_kprobe_ftrace() and may even cause use-after-free:
Failed to disarm kprobe-ftrace at kernel_clone+0x0/0x3c0 (error -2) WARNING: CPU: 5 PID: 137 at kernel/kprobes.c:1135 __disarm_kprobe_ftrace.isra.21+0xcf/0xe0 Modules linked in: testKprobe_007(-) CPU: 5 PID: 137 Comm: rmmod Not tainted 6.1.0-rc4-dirty #18 [...] Call Trace: <TASK> __disable_kprobe+0xcd/0xe0 __unregister_kprobe_top+0x12/0x150 ? mutex_lock+0xe/0x30 unregister_kprobes.part.23+0x31/0xa0 unregister_kprobe+0x32/0x40 __x64_sys_delete_module+0x15e/0x260 ? do_user_addr_fault+0x2cd/0x6b0 do_syscall_64+0x3a/0x90 entry_SYSCALL_64_after_hwframe+0x63/0xcd [...]
For the kprobe-on-ftrace case, we keep the post_handler setting to identify this aggrprobe armed with kprobe_ipmodify_ops. This way we can disarm it correctly.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.4StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.4
- Version 5.10.156StatusunaffectedConstraints<=5.10.*
- Version 5.15.80StatusunaffectedConstraints<=5.15.*
- Version 5.4.225StatusunaffectedConstraints<=5.4.*
- Version 6.0.10StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.4 · < 5.4.225
- ≥ 5.5 · < 5.10.156
- ≥ 5.11 · < 5.15.80
- ≥ 5.16 · < 6.0.10
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A logic flaw in kprobe-on-ftrace caused incorrect handler clearing, which could trigger a warning or potential use-after-free on probe deregistration. The bug affects only highly privileged users managing aggregated kprobes.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-49779 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2363360 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-13007 Advisory
- https://git.kernel.org/stable/c/55788ebbe8b365b4375bd56b4ba7db79d393a370 Patch
- https://git.kernel.org/stable/c/5dd7caf0bdc5d0bae7cf9776b4d739fb09bd5ebb Patch
- https://git.kernel.org/stable/c/7b0007b28dd970176f2e297c06ae63eea2447127 Patch
- https://git.kernel.org/stable/c/7d606ae1abcc3eab5408e42444d789dc7def51b8 Patch
- https://git.kernel.org/stable/c/c49cc2c059b503e962c2f13a806c105f9b757df4 Patch
- https://lore.kernel.org/linux-cve-announce/2025050118-CVE-2022-49779-0263@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49779
- https://www.cve.org/CVERecord?id=CVE-2022-49779
Change history (0)
No recorded changes yet.