PT-2025-51673 · Linux · Linux Kernel
Published
2025-11-11
·
Updated
2026-01-25
·
CVE-2025-68260
CVSS v2.0
4.6
4.6
Medium
| Base vector | Vector | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 6.18 and later
Android Binder driver (Rust implementation)
Description
The first Common Vulnerabilities and Exposures (CVE) has been assigned to Rust code within the Linux kernel. The issue, identified as CVE-2025-68260, affects the Android Binder driver rewrite and is caused by a race condition in an
unsafe block. This race condition can lead to memory corruption of the prev and next pointers in a linked list, potentially causing a kernel panic or system crash. The vulnerability is a result of a flaw in handling concurrency within the unsafe code, where the language's safety guarantees do not apply, and developers must manually ensure correctness. The issue occurs when threads concurrently access and modify a linked list, leading to data corruption. The vulnerability does not currently allow for remote code execution or privilege escalation, and is assessed as a Denial of Service (DoS) issue.Recommendations
For kernel maintainers, ensure upstream patches for CVE-2025-68260 are applied if shipping kernels with the Rust Binder driver enabled (CONFIG ANDROID BINDER IPC RUST).
Fix
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2026-00911
CVE-2025-68260
Affected Products
Linux Kernel
References · 52
- https://nvd.nist.gov/vuln/detail/CVE-2025-68260 · Security Note
- https://ubuntu.com/security/CVE-2025-68260 · Vendor Advisory
- https://cve.org/CVERecord?id=CVE-2025-68260 · Security Note
- https://osv.dev/vulnerability/UBUNTU-CVE-2025-68260 · Vendor Advisory
- https://bdu.fstec.ru/vul/2026-00911 · Security Note
- https://t.me/linkersec/358 · Telegram Post
- https://twitter.com/Kango_V/status/2003914965078683927 · Twitter Post
- https://i.redd.it/gaa9b9spws8g1.jpeg · Reddit Post
- https://twitter.com/emori_lebo/status/2002402688651132955 · Twitter Post
- https://lore.kernel.org/linux-cve-announce/2025121614-CVE-2025-68260-558d@gregkh · Note
- https://twitter.com/Awkiffffff/status/2001544131701870596 · Twitter Post
- https://twitter.com/grok/status/2001371119106789458 · Twitter Post
- https://twitter.com/linkersec/status/2003172285062975513 · Twitter Post
- https://twitter.com/AdithyaA593326/status/2002009932930208158 · Twitter Post
- https://twitter.com/transilienceai/status/2015266113891062051 · Twitter Post