CVE-2025-68329
Last modified
CVE-2025-68329 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close for split VMAs When a VMA is split (e.g., by partial munmap or MAP_FIXED), the kernel calls vm_ops->close on each portion. For trace buffer mappings, this results in ring_buffer_unmap() being called multiple times while ring_buffer_map() was only called once. This causes ring_buffer_unmap() to return -ENODEV on subsequent calls because user_mapped is already 0, triggering a WARN_ON. Trace buffer mappings cannot support partial mappings because the ring buffer structure requires the complete buffer including the meta page. Fix this by adding a may_split callback that returns -EINVAL to prevent VMA splits entirely.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close for split VMAs When a VMA is split (e.g., by partial munmap or MAP_FIXED), the kernel calls vm_ops->close on each portion. For trace buffer mappings, this results in ring_buffer_unmap() being called multiple times while ring_buffer_map() was only called once. This causes ring_buffer_unmap() to return -ENODEV on subsequent calls because user_mapped is already 0, triggering a WARN_ON. Trace buffer mappings cannot support partial mappings because the ring buffer structure requires the complete buffer including the meta page. Fix this by adding a may_split callback that returns -EINVAL to prevent VMA splits entirely.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= cf9f0f7c4c5bb45e7bb270e48bab6f7837825a64, < 922fdd0b755a84f9933b3ca195f60092b6bb88ee; >= cf9f0f7c4c5bb45e7bb270e48bab6f7837825a64, < 45053c12c45f0fb8ef6ab95118dd928d2fec0255; >= cf9f0f7c4c5bb45e7bb270e48bab6f7837825a64, < b042fdf18e89a347177a49e795d8e5184778b5b6 |
| Linux | Linux | 6.10 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-68329?
How severe is CVE-2025-68329?
How do I fix CVE-2025-68329?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-68323In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68324In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68325In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68326In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68327In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68328In the Linux kernel, the following vulnerability has been re…
- CVE-2025-6833The All in One Time Clock Lite – Tracking Employee Time Has …4.3
- CVE-2025-68330In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68331In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68332In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68333In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-68334In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2025-68329?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
