Incomplete Cleanup Affecting libperf-debuginfo package, versions <0:6.12.0-124.8.1.el10_1


Severity

Recommended
medium

Based on CentOS security rating.

Threat Intelligence

EPSS
0.06% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS10-LIBPERFDEBUGINFO-15655282
  • published16 Mar 2026
  • disclosed9 May 2025

Introduced: 9 May 2025

CVE-2025-37849  (opens in a new tab)
CWE-459  (opens in a new tab)

How to fix?

Upgrade Centos:10 libperf-debuginfo to version 0:6.12.0-124.8.1.el10_1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libperf-debuginfo package and not the libperf-debuginfo package as distributed by Centos. See How to fix? for Centos:10 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Tear down vGIC on failed vCPU creation

If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. Note only does this leak the corresponding memory when the vCPU is destroyed but it can also lead to use-after-free if the redistributor device handling tries to walk into the vCPU.

Add the missing cleanup to kvm_arch_vcpu_create(), ensuring that the vGIC vCPU structures are destroyed on error.

CVSS Base Scores

version 3.1