CVE-2025-71102 Details
Description
In the Linux kernel, the following vulnerability has been resolved: scs: fix a wrong parameter in __scs_magic __scs_magic() needs a 'void *' variable, but a 'struct task_struct *' is given. 'task_scs(tsk)' is the starting address of the task's shadow call stack, and '__scs_magic(task_scs(tsk))' is the end address of the task's shadow call stack. Here should be '__scs_magic(task_scs(tsk))'. The user-visible effect of this bug is that when CONFIG_DEBUG_STACK_USAGE is enabled, the shadow call stack usage checking function (scs_check_usage) would scan an incorrect memory range. This could lead 1. **Inaccurate stack usage reporting**: The function would calculate wrong usage statistics for the shadow call stack, potentially showing incorrect value in kmsg. 2. **Potential kernel crash**: If the value of __scs_magic(tsk)is greater than that of __scs_magic(task_scs(tsk)), the for loop may access unmapped memory, potentially causing a kernel panic. However, this scenario is unlikely because task_struct is allocated via the slab allocator (which typically returns lower addresses), while the shadow call stack returned by task_scs(tsk) is allocated via vmalloc(which typically returns higher addresses). However, since this is purely a debugging feature (CONFIG_DEBUG_STACK_USAGE), normal production systems should be not unaffected. The bug only impacts developers and testers who are actively debugging stack usage with this configuration enabled.
A vulnerability in the Linux kernel's handling of the shadow call stack can lead to incorrect memory range scanning by the stack usage checking function. This issue arises because the function __scs_magic() is provided with the wrong type of variable, which, when CONFIG_DEBUG_STACK_USAGE is enabled, can cause inaccurate stack usage reports and potentially allow a kernel crash by accessing unmapped memory. However, this crash scenario is unlikely due to the way memory is allocated for the task structure and the shadow call stack. The vulnerability primarily affects developers and testers debugging stack usage with the relevant configuration active.
Users can update to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the Linux Kernel Archive.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/062774439d442882b44f5eab8c256ad3423ef284 | kernel.org | Patch |
| https://git.kernel.org/stable/c/08bd4c46d5e63b78e77f2605283874bbe868ab19 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1727e8bd69103a68963a5613a0ddb6d8d37df5d3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/57ba40b001be27786d0570dd292289df748b306b | kernel.org | Patch |
| https://git.kernel.org/stable/c/9ef28943471a16e4f9646bc3e8e2de148e7d8d7b | kernel.org | Patch |
| https://git.kernel.org/stable/c/a19fb3611e4c06624fc0f83ef19f4fb8d57d4751 | kernel.org | Patch |
| https://git.kernel.org/stable/c/cfdf6250b63b953b1d8e60814c8ca96c6f9d1c8c | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.8.1, < 5.10.248 >= 5.11, < 5.15.198 >= 5.16, < 6.1.160 >= 6.2, < 6.6.120 >= 6.7, < 6.12.64 >= 6.13, < 6.18.3 5.8 - 6.19 rc1 6.19 rc2 6.19 rc3 6.19 rc4 6.19 rc5 6.19 rc6 6.19 rc7 6.19 rc8 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Mar 25, 2026 | Initial Analysis | [email protected] |
| Jan 19, 2026 | CVE Modified | kernel.org |
| Jan 14, 2026 | New CVE Received | kernel.org |