We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-38434

Revert "riscv: Define TASK_SIZE_MAX for __access_ok()"



Description

In the Linux kernel, the following vulnerability has been resolved: Revert "riscv: Define TASK_SIZE_MAX for __access_ok()" This reverts commit ad5643cf2f69 ("riscv: Define TASK_SIZE_MAX for __access_ok()"). This commit changes TASK_SIZE_MAX to be LONG_MAX to optimize access_ok(), because the previous TASK_SIZE_MAX (default to TASK_SIZE) requires some computation. The reasoning was that all user addresses are less than LONG_MAX, and all kernel addresses are greater than LONG_MAX. Therefore access_ok() can filter kernel addresses. Addresses between TASK_SIZE and LONG_MAX are not valid user addresses, but access_ok() let them pass. That was thought to be okay, because they are not valid addresses at hardware level. Unfortunately, one case is missed: get_user_pages_fast() happily accepts addresses between TASK_SIZE and LONG_MAX. futex(), for instance, uses get_user_pages_fast(). This causes the problem reported by Robert [1]. Therefore, revert this commit. TASK_SIZE_MAX is changed to the default: TASK_SIZE. This unfortunately reduces performance, because TASK_SIZE is more expensive to compute compared to LONG_MAX. But correctness first, we can think about optimization later, if required.

Reserved 2025-04-16 | Published 2025-07-25 | Updated 2025-07-25 | Assigner Linux

Product status

Default status
unaffected

ad5643cf2f699989daa85d909403febd6712fccb before fe30c30bf3bb68d4a4d8c7c814769857b5c973e6
affected

ad5643cf2f699989daa85d909403febd6712fccb before f8b1898748dfeb4f9b67b6a6d661f354b9de3523
affected

ad5643cf2f699989daa85d909403febd6712fccb before 890ba5be6335dbbbc99af14ea007befb5f83f174
affected

Default status
affected

6.10
affected

Any version before 6.10
unaffected

6.12.36
unaffected

6.15.5
unaffected

6.16-rc4
unaffected

References

git.kernel.org/...c/fe30c30bf3bb68d4a4d8c7c814769857b5c973e6

git.kernel.org/...c/f8b1898748dfeb4f9b67b6a6d661f354b9de3523

git.kernel.org/...c/890ba5be6335dbbbc99af14ea007befb5f83f174

cve.org (CVE-2025-38434)

nvd.nist.gov (CVE-2025-38434)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-38434

Support options

Helpdesk Chat, Email, Knowledgebase