CVE Vulnerabilities

CVE-2025-9408

Privilege Context Switching Error

Published: Nov 11, 2025 | Modified: Nov 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows very practical privilege escalation for malicious userspace processes.

Weakness

The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.

Potential Mitigations

References