ima: Fix stack-out-of-bounds in is_bprm_creds_for_exec()
Published May 27, 2026
7.1
HIGHCVSS 3.1
EPSS 0.15%
Description
KASAN reported a stack-out-of-bounds access in ima_appraise_measurement from is_bprm_creds_for_exec:
BUG: KASAN: stack-out-of-bounds in ima_appraise_measurement+0x12dc/0x16a0 Read of size 1 at addr ffffc9000160f940 by task sudo/550 The buggy address belongs to stack of task sudo/550 and is located at offset 24 in frame: ima_appraise_measurement+0x0/0x16a0 This frame has 2 objects: [48, 56) 'file' [80, 148) 'hash'
This is caused by using container_of on the *file pointer. This offset calculation is what triggers the stack-out-of-bounds error.
In order to fix this, pass in a bprm_is_check boolean which can be set depending on how process_measurement is called. If the caller has a linux_binprm pointer and the function is BPRM_CHECK we can determine is_check and set it then. Otherwise set it to false.
Affected products
-
Affected
- ≥ , <
- ≥ , <
-
Affected
- 6.14
Unaffected
- ≥ 0, < 6.14
- ≥ 6.19.4, ≤ 6.19.*
- 7.0
- ≥ 6.14 · < 6.19.4
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2025-71306 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2482189 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209970 Advisory
- https://git.kernel.org/stable/c/377cae9851e8559e9d8b82a78c1ac0abeb18839c Patch
- https://git.kernel.org/stable/c/ab3d16da982a4ebb715d487dbf9dd66e3990d935 Patch
- https://lore.kernel.org/linux-cve-announce/2026052706-CVE-2025-71306-f80c@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-71306
- https://www.cve.org/CVERecord?id=CVE-2025-71306
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data