🛡️ AZL-70150 — kernel

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2025-37878 affecting package kernel 5.15.200.1-1

In the Linux kernel, the following vulnerability has been resolved:

perf/core: Fix WARN_ON(!ctx) in __free_event() for partial init

Move the get_ctx(child_ctx) call and the child_event->ctx assignment to

occur immediately after the child event is allocated. Ensure that

child_event->ctx is non-NULL before any subsequent error path within

inherit_event calls free_event(), satisfying the assumptions of the

cleanup code.

Details:

There's no clear Fixes tag, because this bug is a side-effect of

multiple interacting commits over time (up to 15 years old), not

a single regression.

The code initially incremented refcount then assigned context

immediately after the child_event was created. Later, an early

validity check for child_event was added before the

refcount/assignment. Even later, a WARN_ON_ONCE() cleanup check was

added, assuming event->ctx is valid if the pmu_ctx is valid.

The problem is that the WARN_ON_ONCE() could trigger after the initial

check passed but before child_event->ctx was assigned, violating its

precondition. The solution is to assign child_event->ctx right after

its initial validation. This ensures the context exists for any

subsequent checks or cleanup routines, resolving the WARN_ON_ONCE().

To resolve it, defer the refcount update and child_event->ctx assignment

directly after child_event->pmu_ctx is set but before checking if the

parent event is orphaned. The cleanup routine depends on

event->pmu_ctx being non-NULL before it verifies event->ctx is

non-NULL. This also maintains the author's original intent of passing

in child_ctx to find_get_pmu_context before its refcount/assignment.

[ mingo: Expanded the changelog from another email by Gabriel Shahrouzi. ]

Affected software

AZL-70150 is recorded against 1 package.

  • kernel

Timeline and source

Published on 9 May 2025 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-05-09
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-70150?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-70150 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.