A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HLinux Kernel
OSLinux3.2.85 – 3.3 (excl.)3.16.40 – 3.17 (excl.)3.18.54 – 3.19 (excl.)4.0.0 – 4.9.316 (excl.)4.10 – 4.14.281 (excl.)4.15 – 4.19.245 (excl.)4.20 – 5.4.196 (excl.)5.5.0 – 5.10.118 (excl.)5.11 – 5.15.42 (excl.)5.16 – 5.17.10 (excl.)Netapp Hci Baseboard Management Controller
APPNetapph300sh410sh500sh700s
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Race Condition
References
Related vulnerabilities
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product
RCE przez YAML deserialization w IBM Aspera Faspex
CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓same product
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection
CVE-2020-4006CRITICAL9.1⚠ KEVPL ✓same product
Command Injection w VMware Workspace One Access i Identity Manager