CVE Database
/

CVE-2025-38067

Back to search

CVE-2025-38067

Published: Jun 18, 2025

Modified: May 12, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: rseq: Fix segfault on registration when rseq_cs is non-zero The rseq_cs field is documented as being set to 0 by user-space prior to registration, however this is not currently enforced by the kernel. This can result in a segfault on return to user-space if the value stored in the rseq_cs field doesn't point to a valid struct rseq_cs. The correct solution to this would be to fail the rseq registration when the rseq_cs field is non-zero. However, some older versions of glibc will reuse the rseq area of previous threads without clearing the rseq_cs field and will also terminate the process if the rseq registration fails in a secondary thread. This wasn't caught in testing because in this case the leftover rseq_cs does point to a valid struct rseq_cs. What we can do is clear the rseq_cs field on registration when it's non-zero which will prevent segfaults on registration and won't break the glibc versions that reuse rseq areas on thread creation.

VendorProductVersions

Linux

Linux

affected
d7822b1e24f2df5df98c76f0e94a5416349ff759 - < 48900d839a3454050fd5822e34be8d54c4ec9b86
affected
d7822b1e24f2df5df98c76f0e94a5416349ff759 - < 3e4028ef31b69286c9d4878cee0330235f53f218
affected
d7822b1e24f2df5df98c76f0e94a5416349ff759 - < b2b05d0dc2f4f0646922068af435aed5763d16ba
affected
d7822b1e24f2df5df98c76f0e94a5416349ff759 - < eaf112069a904b6207b4106ff083e0208232a2eb
affected
d7822b1e24f2df5df98c76f0e94a5416349ff759 - < f004f58d18a2d3dc761cf973ad27b4a5997bd876

+2 more versions

Linux

Linux

affected
4.18
unaffected
0 - < 4.18
unaffected
5.10.240 - <= 5.10.*
unaffected
5.15.189 - <= 5.15.*
unaffected
6.1.146 - <= 6.1.*

+4 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now