CVE-2025-37822

Source
https://cve.org/CVERecord?id=CVE-2025-37822
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37822.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-37822
Downstream
Published
2025-05-08T06:26:16.209Z
Modified
2026-05-28T03:53:21.021197891Z
Summary
riscv: uprobes: Add missing fence.i after building the XOL buffer
Details

In the Linux kernel, the following vulnerability has been resolved:

riscv: uprobes: Add missing fence.i after building the XOL buffer

The XOL (execute out-of-line) buffer is used to single-step the replaced instruction(s) for uprobes. The RISC-V port was missing a proper fence.i (i$ flushing) after constructing the XOL buffer, which can result in incorrect execution of stale/broken instructions.

This was found running the BPF selftests "testprogs: uprobeautoattach, attach_probe" on the Spacemit K1/X60, where the uprobes tests randomly blew up.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37822.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
74784081aac8a0f3636965fc230e2d3b7cc123c6
Fixed
be6d98766ac952d38241d5a5b213f363afa421c3
Fixed
b6d8d4d01ca8514fa89b05355f296758a91e2297
Fixed
77c956152a3a7c7a18b68f3654f70565b2181d03
Fixed
bcf6d3158c5902d92b6d62335af4422b7bf7c4e2
Fixed
1dbb95a36499374c51b47ee8ae258a8862c20978
Fixed
7d1d19a11cfbfd8bae1d89cc010b2cc397cd0c48

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37822.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.12.0
Fixed
5.15.200
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.163
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.121
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.26
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.14.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37822.json"