Linux Kernel Vulnerability Affecting User-Space Registration
CVE-2025-38067

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
18 June 2025

What is CVE-2025-38067?

A vulnerability in the Linux kernel related to the rseq (restartable sequences) functionality can lead to segmentation faults during the registration process. Specifically, the rseq_cs field is meant to be set to zero by user-space prior to registration, but current kernel implementations do not enforce this rule. As a result, if a non-zero value is stored, it may not point to a valid struct rseq_cs, possibly causing a segmentation fault upon return to user-space. This issue is compounded in older versions of glibc, which may not clear the rseq_cs field when reusing rseq areas across threads, thereby increasing the risk of process termination. To resolve this, the registration process should enforce a check for a non-zero rseq_cs field, ensuring that invalid pointers are not utilized, thus maintaining system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux d7822b1e24f2df5df98c76f0e94a5416349ff759 < 48900d839a3454050fd5822e34be8d54c4ec9b86

Linux d7822b1e24f2df5df98c76f0e94a5416349ff759 < 3e4028ef31b69286c9d4878cee0330235f53f218

Linux d7822b1e24f2df5df98c76f0e94a5416349ff759

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.