🛡️ OESA-2025-1247 — kernel (CVE-2024-56606 +7 more)

🟠 CVSS 8.0 — High ✅ No Known Exploit OSV
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

kernel security update

The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

af_packet: avoid erroring out after sock_init_data() in packet_create()

After sock_init_data() the allocated sk object is attached to the provided

sock object. On error, packet_create() frees the sk object leaving the

dangling pointer in the sock object on return. Some other code may try

to use this pointer and cause use-after-free.(CVE-2024-56606)

In the Linux kernel, the following vulnerability has been resolved:

iio: imu: kmx61: fix information leak in triggered buffer

The 'buffer' local array is used to push data to user space from a

triggered buffer, but it does not set values for inactive channels, as

it only uses iio_for_each_active_channel() to assign new values.

Initialize the array to zero before using it to avoid pushing

uninitialized information to userspace.(CVE-2024-57908)

In the Linux kernel, the following vulnerability has been resolved:

iio: pressure: zpa2326: fix information leak in triggered buffer

The 'sample' local struct is used to push data to user space from a

triggered buffer, but it has a hole between the temperature and the

timestamp (u32 pressure, u16 temperature, GAP, u64 timestamp).

This hole is never initialized.

Initialize the struct to zero before using it to avoid pushing

uninitialized information to userspace.(CVE-2024-57912)

In the Linux kernel, the following vulnerability has been resolved:

memcg: fix soft lockup in the OOM process

A soft lockup issue was found in the product with about 56,000 tasks were

in the OOM cgroup, it was traversing them when the soft lockup was

triggered.

watchdog: BUG: soft lockup - CPU#2 stuck for 23s! [VM Thread:1503066]

CPU: 2 PID: 1503066 Comm: VM Thread Kdump: loaded Tainted: G

Hardware name: Huawei Cloud OpenStack Nova, BIOS

RIP: 0010:console_unlock+0x343/0x540

RSP: 0000:ffffb751447db9a0 EFLAGS: 00000247 ORIG_RAX: ffffffffffffff13

RAX: 0000000000000001 RBX: 0000000000000000 RCX: 00000000ffffffff

RDX: 0000000000000000 RSI: 0000000000000004 RDI: 0000000000000247

RBP: ffffffffafc71f90 R08: 0000000000000000 R09: 0000000000000040

R10: 0000000000000080 R11: 0000000000000000 R12: ffffffffafc74bd0

R13: ffffffffaf60a220 R14: 0000000000000247 R15: 0000000000000000

CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033

CR2: 00007f2fe6ad91f0 CR3: 00000004b2076003 CR4: 0000000000360ee0

DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000

DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400

Call Trace:

vprintk_emit+0x193/0x280

printk+0x52/0x6e

dump_task+0x114/0x130

mem_cgroup_scan_tasks+0x76/0x100

dump_header+0x1fe/0x210

oom_kill_process+0xd1/0x100

out_of_memory+0x125/0x570

mem_cgroup_out_of_memory+0xb5/0xd0

try_charge+0x720/0x770

mem_cgroup_try_charge+0x86/0x180

mem_cgroup_try_charge_delay+0x1c/0x40

do_anonymous_page+0xb5/0x390

handle_mm_fault+0xc4/0x1f0

This is because thousands of processes are in the OOM cgroup, it takes a

long time to traverse all of them. As a result, this lead to soft lockup

in the OOM process.

To fix this issue, call 'cond_resched' in the 'mem_cgroup_scan_tasks'

function per 1000 iterations. For global OOM, call

'touch_softlockup_watchdog' per 1000 iterations to avoid this issue.(CVE-2024-57977)

In the Linux kernel, the following vulnerability has been resolved:

net: hns3: fixed hclge_fetch_pf_reg accesses bar space out of bounds issue

The TQP BAR space is divided into two segments. TQPs 0-1023 and TQPs

1024-1279 are in different BAR space addresses. However,

hclge_fetch_pf_reg does not distinguish the tqp space information when

reading the tqp space information. When the number of TQPs is greater

than 1024, access bar space overwriting occurs.

The problem of different segments has been considered during the

initialization of tqp.io_base. Therefore, tqp.io_base is directly used

when the queue is read in hclge_fetch_pf_reg.

The error message:

Unable to handle kernel paging request at virtual address ffff800037200000

pc : hclge_fetch_pf_reg+0x138/0x250 [hclge]

lr : hclge_get_regs+0x84/0x1d0 [hclge]

Call trace:

hclge_fetch_pf_reg+0x138/0x250 [hclge]

hclge_get_regs+0x84/0x1d0 [hclge]

hns3_get_regs+0x2c/0x50 [hns3]

ethtool_get_regs+0xf4/0x270

dev_ethtool+0x674/0x8a0

dev_ioctl+0x270/0x36c

sock_do_ioctl+0x110/0x2a0

sock_ioctl+0x2ac/0x530

__arm64_sys_ioctl+0xa8/0x100

invoke_syscall+0x4c/0x124

el0_svc_common.constprop.0+0x140/0x15c

do_el0_svc+0x30/0xd0

el0_svc+0x1c/0x2c

el0_sync_handler+0xb0/0xb4

el0_sync+0x168/0x180(CVE-2025-21650)

In the Linux kernel, the following vulnerability has been resolved:

net: hns3: don't auto enable misc vector

Currently, there is a time window between misc irq enabled

and service task inited. If an interrupte is reported at

this time, it will cause warning like below:

[ 16.324639] Call trace:

[ 16.324641] __que

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.

Affected software

OESA-2025-1247 is recorded against 1 package.

  • kernel (fixed in 5.10.0-252.0.0.156.oe2203sp4)

Timeline and source

Published on 7 March 2025 and last revised on 18 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.openeuler.org (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-03-07
Updated 2026-08-20
Modified 2026-08-18
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 5.10.0-252.0.0.156.oe2203sp4

Similar Threats

Site Security Check

Is kernel part of your stack?

OESA-2025-1247 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesopenEuleropenEuler 2025